Frame Injection Vulnerability won't affect OW?

Yosuke Arai cbq59080 at pop06.odn.ne.jp
Fri Jul 2 06:03:20 PDT 2004


Secunia.com has pointed out "Multiple Browsers Frame Injection 
Vulnerability" affect many kinds of browsers.
http://secunia.com/advisories/11978/
The list of vulnerable browsers includes Safari, but not OmniWeb.
I gave the exploit a try.
http://secunia.com/multiple_browsers_frame_injection_vulnerability_test/
Safari 1.2.2 (and also IE 5.2.3) tested vulnerable, whereas OW 4.5 and 
5.0 beta 8 didn't seem to be affected. Is OW safe in regards to this 
vulnerability? Could someone from OmniGroup give a comment on this?

Yosuke Arai



More information about the OmniWeb-l mailing list