The host is installed with Apple Safari before 6.0 and is prone to a cross site scripting vulnerability. A flaw is present in the application, which fails to properly handle location.href property. Successful exploitation could allow attackers to inject arbitrary web script or HTML.