CVE-2011-0167 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 3.3% (pctl 88)
Patch early
A public exploit exists.
Description
The windows functionality in WebKit in Apple Safari before 5.0.4 allows remote attackers to bypass the Same Origin Policy, and force the upload of arbitrary local files from a client computer, via a crafted web site.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 3.34% — more likely to be exploited than 88% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2011-03-11 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| apple | safari |
| apple | webkit |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | WebKit 1.2.x - Local Webpage Cross Domain Information Disclosure | 2011-03-09 |
References
- http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html
- http://support.apple.com/kb/HT4566
- http://www.securityfocus.com/bid/46816
- http://www.securitytracker.com/id?1025183
- http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html
- http://support.apple.com/kb/HT4566
- http://www.securityfocus.com/bid/46816
- http://www.securitytracker.com/id?1025183
→ the Explorer · watch your stack · NVD