Web Hack List

Collected research

Same Origin Bypass in Adobe Reader CVE-2014-8453

InsertScript: Multiple PDF Vulnerabilities

Four Adobe Reader flaws presented at HackPra: GoToE and GoToR actions ignore protocol restrictions so a PDF can reach file:// and other local schemes, app.trustPropagatorFunction can be abused to reach privileged JavaScript and read local files, XFA loadXML allows XXE, and FormCalc GET, POST and PUT fetch URLs with the victim's cookies and follow redirects across origins, turning the browser into a proxy and defeating CSRF tokens.

Record

Document
InsertScript: Multiple PDF Vulnerabilities
Published by
insert-script.blogspot.com
Topic
Browser

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of insert-script.blogspot.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .