Web Hack List

Top 10 winner

Universal XSS in Adobe's Acrobat Reader Plugin

[Full-disclosure] Adobe Acrobat Reader Plugin - Multiple Vulnerabilities

Adobe's Acrobat Reader browser plugin accepts #FDF, #XML and #XFDF fragments on any PDF URL, so a link to any site's own PDF makes the plugin issue attacker-chosen requests. That yields universal CSRF across Firefox, IE and Opera, universal XSS in Firefox via #FDF=javascript:, forced file downloads, credential theft through res:// named pipes, a DoubleFree reachable for possible code execution, and an IE memory-exhaustion DoS.

Record

Document
[Full-disclosure] Adobe Acrobat Reader Plugin - Multiple Vulnerabilities
Researcher
Stefano Di Paola
Published by
Full Disclosure / Neohapsis
Date
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Stefano Di Paola, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .