Korean
<< Back
VID 28165
Severity 30
Port 139,445
Protocol TCP
Class SMB
Detailed Description A version of Macromedia Flash Player before 9.0.28.0 has been installed on the host. Macromedia Flash Player versions prior to 9.0.28.0 are vulnerable to multiple HTTP header injection vulnerabilities. A successful attack could allow a remote attacker to perform arbitrary HTTP requests facilitating cross-site request forgery, cross-site scripting, HTTP request smuggling, and other attacks against a user who visits a malicious web site.

* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of these condition will result in the check not being performed and a False Negative for all vulnerable hosts.

* References:
http://www.adobe.com/support/security/advisories/apsa06-01.html
http://www.adobe.com/support/security/bulletins/apsb06-18.html
http://www.rapid7.com/advisories/R7-0026.jsp

* Platforms Affected:
Adobe Systems Incorporated, Macromedia Flash Player for Windows versions prior to 9.0.28.0
Apple Mac OS X Any version
Linux Any version
Microsoft Windows Any version
Recommendation Upgrade to the latest version of Macromedia Flash Player (9.0.28.0 or later), available from the Adobe Web site at http://www.adobe.com/shockwave/download/download.cgi?P1_Prod_Version=ShockwaveFlash
Related URL CVE-2006-5330 (CVE)
Related URL 20592,20593 (SecurityFocus)
Related URL 29634 (ISS)