The host is installed with Apple Safari before 6.1 and is prone to a cross site scripting vulnerability. A flaw is present in the application, which fails to properly validate content before a paste or a drag and drop operation. Successful exploitation could allow scripts contained in the selection to be executed in the context of the new site.