VID |
28165 |
Severity |
30 |
Port |
139,445 |
Protocol |
TCP |
Class |
SMB |
Detailed Description |
A version of Macromedia Flash Player before 9.0.28.0 has been installed on the host. Macromedia Flash Player versions prior to 9.0.28.0 are vulnerable to multiple HTTP header injection vulnerabilities. A successful attack could allow a remote attacker to perform arbitrary HTTP requests facilitating cross-site request forgery, cross-site scripting, HTTP request smuggling, and other attacks against a user who visits a malicious web site.
* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of these condition will result in the check not being performed and a False Negative for all vulnerable hosts.
* References: http://www.adobe.com/support/security/advisories/apsa06-01.html http://www.adobe.com/support/security/bulletins/apsb06-18.html http://www.rapid7.com/advisories/R7-0026.jsp
* Platforms Affected: Adobe Systems Incorporated, Macromedia Flash Player for Windows versions prior to 9.0.28.0 Apple Mac OS X Any version Linux Any version Microsoft Windows Any version |
Recommendation |
Upgrade to the latest version of Macromedia Flash Player (9.0.28.0 or later), available from the Adobe Web site at http://www.adobe.com/shockwave/download/download.cgi?P1_Prod_Version=ShockwaveFlash |
Related URL |
CVE-2006-5330 (CVE) |
Related URL |
20592,20593 (SecurityFocus) |
Related URL |
29634 (ISS) |
|