Macromedia Flash Player Flash Cookie可预测文件定位漏洞

Macromedia Flash Player Flash Cookie可预测文件定位漏洞

漏洞ID 1107535 漏洞类型 未知
发布时间 2003-10-24 更新时间 2005-10-20
图片[1]-Macromedia Flash Player Flash Cookie可预测文件定位漏洞-安全小百科CVE编号 CVE-2003-1017
图片[2]-Macromedia Flash Player Flash Cookie可预测文件定位漏洞-安全小百科CNNVD-ID CNNVD-200401-006
漏洞平台 Windows CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/23298
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200401-006
|漏洞详情
MacromediaFlashPlayer支持对flash文件的播放。MacromediaFlashPlayer存储FlashCookie文件在可预测位置,结合其他漏洞可导致在系统上执行恶意代码。MacromediaFlashPlayer把FlashCookie文件(.sol)保存在可预测客户端位置中,结合其他漏洞,如通过file://URI进行引用的问题,可导致客户端浏览器执行包含在Cookie中的恶意HTML和脚本代码。造成敏感信息泄露。
|漏洞EXP
source: http://www.securityfocus.com/bid/8900/info

Macromedia Flash Player is reported to store Flash cookies (.sol files) in a predictable location on client systems. Other attacks are possible given the ability to store content on a system in a predictable location, such as referencing the content via a file:// URI. This is compounded by the fact that an attacker could include HTML and script code in the cookie, which may be interpreted by Internet Explorer or possibly other browsers. In the example of Internet Explorer, such content would be interpreted in the context of the Local Zone. Successful exploitation would still require the attacker to guess the local username of the victim.

This issue is reported to affect versions of the player for Microsoft Windows operating systems. Other versions may also be affected. Macromedia Director MX is similarly affected.

This issue affects versions of the player prior to 7.0.19.0. 

ftp://%@/../../../../Application Data/Macromedia/Flash
Player/YOURDOMAINNAME.TLDYOURDOMAINNAME.sol
|参考资料

来源:BID
名称:8900
链接:http://www.securityfocus.com/bid/8900
来源:www.macromedia.com
链接:http://www.macromedia.com/devnet/security/security_zone/mpsb03-08.html
来源:XF
名称:flash-file-predictable-location(14013)
链接:http://xforce.iss.net/xforce/xfdb/14013
来源:www.macromedia.com
链接:http://www.macromedia.com/devnet/security/security_zone/mpsb03-08.html

相关推荐: Savant Web Server NULL Vulnerability

Savant Web Server NULL Vulnerability 漏洞ID 1104451 漏洞类型 Input Validation Error 发布时间 1999-12-28 更新时间 1999-12-28 CVE编号 N/A CNNVD-ID N…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享