Collected research
Same Origin Bypass in Adobe Reader CVE-2014-8453
InsertScript: Multiple PDF Vulnerabilities
Four Adobe Reader flaws presented at HackPra: GoToE and GoToR actions ignore protocol restrictions so a PDF can reach file:// and other local schemes, app.trustPropagatorFunction can be abused to reach privileged JavaScript and read local files, XFA loadXML allows XXE, and FormCalc GET, POST and PUT fetch URLs with the victim's cookies and follow redirects across origins, turning the browser into a proxy and defeating CSRF tokens.
Record
- Document
- InsertScript: Multiple PDF Vulnerabilities
- Published by
- insert-script.blogspot.com
- Topic
- Browser
In the archive
Related sources
- PDF JavaScript proof-of-concept
- PDF XXE proof-of-concept
- PDF XFA proof-of-concept
- The life of an Adobe Reader JavaScript bug Advisory
Tags
This page is the archive's own catalogue record. The research is the work of insert-script.blogspot.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .