Arbitrary Database Access via WebSQL Table Rename in Apple Safari

Arbitrary Database Access via WebSQL Table Rename in Apple Safari

CVE-2015-3727 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly restrict rename operations on WebSQL tables, which allows remote attackers to access an arbitrary web site's database via a crafted web site.

Learn more about our Cis Benchmark Audit For Apple Ios.