Apple's Safari web browser ignores the Content-type: sent by the web server. As a result, plain text is rendered as HTML. This is obviously undesirable; a text file could contain HTML and carry out a cross site scripting attack. Version 1.2.4 v125.12 found vulnerable.
Apple's Safari web browser ignores the Content-type: sent by the web server. As a result, plain text is rendered as HTML. This is obviously undesirable; a text file could contain HTML and carry out a cross site scripting attack. Version 1.2.4 v125.12 found vulnerable.