Latest Comments
"it's good one "
by khanbhai | Nov 22, 2008 9:00 PM
 
"when i login to face book it tells me i am cookies enabled what does this mean"
by celeste | Nov 21, 2008 5:15 PM
 
"Hi this is the mail I received Brett Karpman show details Nov 17 (3 days ago) Reply Atten..."
by Rodney Churchyard | Nov 20, 2008 6:13 PM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"Umm. no. The 6.5 product is mounting the offline VM image and performing a scan for patch ..."
by eric | Nov 20, 2008 8:15 AM

Adobe patches prevent cross-site scripting attacks via Flash

  • Email a Friend
  • Print Page
By
Jan 18, 2008 4:10 PM
Tags: Adobe | patches | prevent | cross-site | scripting | attacks | via | Flash
The San Jose, Calif.-based productivity application vendor patched vulnerabilities in Connect Enterprise Server 6, Dreamweaver versions CS3 and 8, and Contribute CS3 and 4 to fix issues that can allow XSS attacks on end-users' PCs.

One flaw, caused by input validation errors in Dreamweaver and Contribute, affects users who have installed the Insert Flash Video command.

Adobe credited Google security researcher Rich Cannings with reporting both flaws, which can be found in Shockwave Flash files on websites.

Cannings told SCMagazineUS.com earlier this month that there are hundreds of thousands of vulnerable SWF files on the web.

Cannings and an Adobe representative could not be immediately reached for comment.

Jeremiah Grossman, chief technology officer at WhiteHat Security, told SCMagazineUS.com today that XSS is “the No. 1 type of vulnerability out there now.”

“There are many Flash files out there that are vulnerable to this type of attack. There are thousands, and potentially hundreds of thousands of them, and they're all going to have to be rebuilt,” he said. “[The patch] was the vendor-side problem, but they're going to have to wait for the website owners and the website creators to catch up with them.”

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
 
Patch Management Whitepapers