Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2008-1654
StatusCandidate
DescriptionInteraction error between Adobe Flash and multiple Universal Plug and Play (UPnP) services allow remote attackers to perform Cross-Site Request Forgery (CSRF) style attacks by using the Flash navigateToURL function to send a SOAP message to a UPnP control point, as demonstrated by changing the primary DNS server.
PhaseAssigned (02.04.2008)
SecurityVulns:Adobe Flash Player multiple security vulnerabilities
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1654
ReferencesBUGTRAQ : 20080113 Hacking The Interwebs
 CERT-VN : VU#347812
 FULLDISC : 20080113 Hacking The Interwebs
 MISC : http://www.gnucitizen.org/blog/hacking-the-interwebs/

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru