Top 10 winner
Universal XSS in Adobe's Acrobat Reader Plugin
[Full-disclosure] Adobe Acrobat Reader Plugin - Multiple Vulnerabilities
Adobe's Acrobat Reader browser plugin accepts #FDF, #XML and #XFDF fragments on any PDF URL, so a link to any site's own PDF makes the plugin issue attacker-chosen requests. That yields universal CSRF across Firefox, IE and Opera, universal XSS in Firefox via #FDF=javascript:, forced file downloads, credential theft through res:// named pipes, a DoubleFree reachable for possible code execution, and an IE memory-exhaustion DoS.
Record
- Document
- [Full-disclosure] Adobe Acrobat Reader Plugin - Multiple Vulnerabilities
- Researcher
- Stefano Di Paola
- Published by
- Full Disclosure / Neohapsis
- Date
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Stefano Di Paola, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .