The host is installed with Apple Safari 4.0 before 4.1 and is prone to a cross site scripting vulnerability. A flaw is present in the application, which fails to handle UTF-7 encoded text. Successful exploitation could allow attackers to inject arbitrary code or crash the service.