Apple iOS 'content-disposition' Message Header Cross-Site Scripting Vulnerability
Release date:
Updated on:
Affected Systems:
Apple iOS
Description:
--------------------------------------------------------------------------------
Bugtraq id: 68969
IOS is an operating system developed by Apple for mobile devices. It supports iPhone, iPod touch, iPad, and Apple TV.
Apple iOS does not effectively filter the data in the 'content-disposition' header. There is a cross-site scripting vulnerability in implementation. Attackers can exploit this vulnerability to execute arbitrary code in the context of the affected application.
<* Source: Yorick
Superhei
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apple
-----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.apple.com/support/downloads/
This article permanently updates the link address: