WebKit, as used in Apple iOS before 8.3 and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, does not properly handle the userinfo field in FTP URLs, which allows remote attackers to trigger incorrect resource access via unspecified vectors.
2015-04-10T14:59:39.713
2025-04-12T10:46:40.837
Deferred
CVSSv2: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:N/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | apple | iphone_os | ≤ 8.2 | Yes |
Application | apple | safari | ≤ 6.2.4 | Yes |
Application | apple | safari | 7.0 | Yes |
Application | apple | safari | 7.0.1 | Yes |
Application | apple | safari | 7.0.2 | Yes |
Application | apple | safari | 7.0.3 | Yes |
Application | apple | safari | 7.0.4 | Yes |
Application | apple | safari | 7.0.5 | Yes |
Application | apple | safari | 7.0.6 | Yes |
Application | apple | safari | 7.1.0 | Yes |
Application | apple | safari | 7.1.1 | Yes |
Application | apple | safari | 7.1.2 | Yes |
Application | apple | safari | 7.1.3 | Yes |
Application | apple | safari | 7.1.4 | Yes |
Application | apple | safari | 8.0.0 | Yes |
Application | apple | safari | 8.0.1 | Yes |
Application | apple | safari | 8.0.2 | Yes |
Application | apple | safari | 8.0.3 | Yes |
Application | apple | safari | 8.0.4 | Yes |