vendor:
Flash Player
by:
0a29406d9794e4f9b30b3c5d6702c708
N/A
CVSS
N/A
Command Execution
78
CWE
Product Name: Flash Player
Affected Version From: 9.0.151.0
Affected Version To: 10.0.12.36
Patch Exists: YES
Related CWE: CVE-2008-5499
CPE: a:adobe:flash_player:10.0.12.36
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2008
Adobe Flash Player ActionScript Launch Command Execution Vulnerability
This module exploits a vulnerability in Adobe Flash Player for Linux, version 10.0.12.36 and 9.0.151.0 and prior. An input validation vulnerability allows command execution when the browser loads a SWF file which contains shell metacharacters in the arguments to the ActionScript launch method. The victim must have Adobe AIR installed for the exploit to work. This module was tested against version 10.0.12.36 (10r12_36).
Mitigation:
Adobe has released a security update to address this vulnerability. Users are advised to update to the latest version of Adobe Flash Player.