Adobe Document Server for Reader Extensions 6.0 allows remote authenticated users to inject arbitrary web script via a leading (1) ftp or (2) http URI in the ReaderURL variable in the "Update Download Site" section of ads-readerext. NOTE: it is not clear whether the vendor advisory addresses this issue. In addition, since the issue requires administrative privileges to exploit, it is not clear whether this crosses security boundaries.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2006-1785 | Adobe Document Server for Reader Extensions 6.0 allows remote authenticated users to inject arbitrary web script via a leading (1) ftp or (2) http URI in the ReaderURL variable in the "Update Download Site" section of ads-readerext. NOTE: it is not clear whether the vendor advisory addresses this issue. In addition, since the issue requires administrative privileges to exploit, it is not clear whether this crosses security boundaries. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T17:27:28.609Z
Reserved: 2006-04-13T04:00:00.000Z
Link: CVE-2006-1785
No data.
Status : Deferred
Published: 2006-04-13T22:02:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2006-1785
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD