Apple Safari before 6.0 does not properly handle the autocomplete attribute of a password input element, which allows remote attackers to bypass authentication by leveraging an unattended workstation.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.html | vendor advisory |
http://support.apple.com/kb/HT5503 | |
http://www.securityfocus.com/bid/54688 | vdb entry |
http://lists.apple.com/archives/security-announce/2012/Jul/msg00000.html | vendor advisory |
http://support.apple.com/kb/HT5400 | vendor advisory |