|
|
Article: NEW YORK OFFICE OF CYBER SECURITY AND CRITICAL INFRASTRUCTURE COORDINATION ISSUES ADVISORY THAT ADOBE ACROBAT READER PLUGIN IS PRONE TO CROSS-SITE SCRIPTING ATTACKS
- Article from:
- US Fed News Service, Including US State News
- Article date:
- January 5, 2007
CopyrightCopyright © HT Media Ltd. All Rights Reserved. Provided by ProQuest LLC. (Hide copyright information)
|
The New York State Office of Cyber Security and Critical Infrastructure Coordination issued the following advisory:
CSCIC ADVISORY NUMBER:2007-001
DATE(S) ISSUED:1/05/2007
SUBJECT:Adobe Acrobat Reader Plugin is Prone to Cross-Site Scripting Attacks
OVERVIEW:
A vulnerability has been found in multiple versions of the Adobe Acrobat Reader Plugin, which allows users to view Portable Document Format (PDF) files via a web browser such as Internet Explorer or Firefox. The Adobe Acrobat Reader installs the plugin by default. Please note that only the Adobe Acrobat Reader Plugin is vulnerable to this attack. This vulnerability can be exploited if an attacker can convince a user to click on a ...