Adobe Flex SDK 'index.template.html' Cross Site Scripting Vulnerability
BID:36087
Info
Adobe Flex SDK 'index.template.html' Cross Site Scripting Vulnerability
| Bugtraq ID: | 36087 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-1879 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 19 2009 12:00AM |
| Updated: | Aug 21 2009 03:56PM |
| Credit: | Adam Bixby of Gotham Digital Science |
| Vulnerable: |
Adobe Flex SDK 3.0.2 Adobe Flex SDK 3.0.1 Adobe Flex SDK 3.3 |
| Not Vulnerable: |
Adobe Flex SDK 3.4 |
Discussion
Adobe Flex SDK 'index.template.html' Cross Site Scripting Vulnerability
Adobe Flex SDK is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input to express-install template files.
An attacker could exploit this vulnerability to execute arbitrary script code in the context of a web application built using the SDK. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to Flex SDK 3.4 are vulnerable.
Adobe Flex SDK is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input to express-install template files.
An attacker could exploit this vulnerability to execute arbitrary script code in the context of a web application built using the SDK. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to Flex SDK 3.4 are vulnerable.
Exploit / POC
Adobe Flex SDK 'index.template.html' Cross Site Scripting Vulnerability
To exploit this issue, an attacker must entice a victim into following a malicious URI.
The following example URI is available:
http://www.example.com/Flex/index.template.html?"/></object><script>alert('XSS')</script>
To exploit this issue, an attacker must entice a victim into following a malicious URI.
The following example URI is available:
http://www.example.com/Flex/index.template.html?"/></object><script>alert('XSS')</script>
Solution / Fix
Adobe Flex SDK 'index.template.html' Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Adobe Flex SDK 'index.template.html' Cross Site Scripting Vulnerability
References:
References: