The host is installed with Apple Safari before 3.1.1 and is prone to a cross site scripting vulnerability. A flaw is present in the application, which fails to properly handle a crafted URL with a colon in the hostname portion. Successful exploitation allows remote attackers to inject arbitrary web script or HTML.