CVE-2007-3761
Cross-site scripting (XSS) vulnerability in Safari in Apple iPhone 1.1.1 allows remote attackers to inject arbitrary web script or HTML by causing Javascript events to be applied to a frame in another domain.
Date published : 2007-09-27
http://lists.apple.com/archives/security-announce/2007/Sep/msg00001.html