The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote attackers to read arbitrary files via a crafted DTD, as demonstrated by a file:///etc/passwd URL in an entity declaration, related to an "XXE attack."
Threat-Mapped Scoring
Score: 0.0
Priority: Unclassified
EPSS
Score: 0.05627 Percentile:
0.89926
CVSS Scoring
CVSS v3.1 Score: 7.5
Severity: HIGH
Mapped CWE(s)
CWE-611
: Improper Restriction of XML External Entity Reference
All CAPEC(s)
CAPEC-221: Data Serialization External Entities Blowup