• About Us
  • Search
  • Compatibility
  • Forums
  • Archive
  • Channels
  • Home
  • Search
  • Member List
  • Calendar
  • Help

Current time: 07-24-2008, 07:34 PM Hello There, Guest! (Login — Register)


Warp2Search - Your Daily Tech News Service / General Discussion / Submit News / Acrobat Reader suffers major XSS flaw

Post Reply  Post Thread 
Threaded Mode | Linear Mode
Acrobat Reader suffers major XSS flaw
Author Message
Jackass
Posting Freak
*****


Posts: 3,215
Group: Registered
Joined: Dec 2005
Status: Offline
Reputation: 0
Post: #1
Acrobat Reader suffers major XSS flaw

An ill-conceived feature in the widely used Acrobat Reader renders many websites vulnerable to client Cross Site Scripting. The flaw requires user action but is easily exploited in numerous ways.
The Universal PDF XSS flaw was discovered by Stefano Di Paola and Giorgio Fedon, and uses a feature known as "Open Parameters" in Acrobat Reader to permit Cross Site Scripting with JavaScript injection. Symantec's Hon Lau has written a good blog entry on the issue.
SecurityFocus



I'm proud to be Canadian
01-08-2007 04:22 AM
Visit this user's website Find all posts by this user Quote this message in a reply
« Next Oldest | Next Newest »
Post Reply  Post Thread 

View a Printable Version
Send this Thread to a Friend
Subscribe to this Thread | Add Thread to Favorites

Forum Jump:

Contact Us | Warp2Search.Net | Return to Top | Return to Content | RSS Syndication

Powered By MyBB
Copyright © 2002-2008 MyBB Group