vendor:
Multiple Adobe Products
by:
Thomas Sluyter
7,5
CVSS
HIGH
XML Injection
20
CWE
Product Name: Multiple Adobe Products
Affected Version From: BlazeDS 3.2 and earlier versions, LiveCycle 9.0, 8.2.1, and 8.0.1, LiveCycle Data Services 3.0, 2.6.1, and 2.5.1, Flex Data Services 2.0.1, ColdFusion 9.0, 8.0.1, 8.0, and 7.0.2
Affected Version To:
Patch Exists: YES
Related CWE: 2009-3960
CPE:
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Server 2003, ColdFusion 8.0 Enterprise
2017
Adobe XML Injection file content disclosure
This exploit allows attackers to read files that are otherwise inaccessible by exploiting a known XML injection vulnerability in a number of Adobe products. The attack works with BlazeDS 3.2 and earlier versions, LiveCycle 9.0, 8.2.1, and 8.0.1, LiveCycle Data Services 3.0, 2.6.1, and 2.5.1, Flex Data Services 2.0.1, ColdFusion 9.0, 8.0.1, 8.0, and 7.0.2.
Mitigation:
Adobe has released a security bulletin (APSB10-05) to address this vulnerability. Users should update their Adobe products to the latest version.