Apple Safari 1.2.4 does not obey the Content-type field in the HTTP header and renders text as HTML, which allows remote attackers to inject arbitrary web script or HTML and perform cross-site scripting (XSS) attacks.
From 神龙GPT (AIGC)
Apple Safari 1.2.4 不遵守 HTTP 头中的 Content-type 字段,将其渲染为 HTML,这允许远程攻击者注入任意的 Web 脚本或 HTML 并执行跨站脚本攻击(XSS)。