WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle the Attr.style accessor, which allows remote attackers to bypass the Same Origin Policy and inject Cascading Style Sheets (CSS) token sequences via a crafted web site.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: apple
Published:
Updated: 2024-08-06T21:43:15.359Z
Reserved: 2010-12-23T00:00:00
Link: CVE-2011-0161

No data.

Status : Deferred
Published: 2011-03-11T22:55:02.947
Modified: 2025-04-11T00:51:21.963
Link: CVE-2011-0161

No data.