Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Adobe Flash Player SWFs in Dreamweaver and Acrobat Unspecified Cross-Site Scripting Vulnerabilities

Adobe Dreamweaver and Acrobat Connect include pre-generated SWF files that are prone to cross-site scripting vulnerabilities.

An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.

The affected SWF files are included with Dreamweaver CS3 and Acrobat Connect. However, the applications themselves are not affected.







 

Privacy Statement
Copyright 2009, SecurityFocus