OSVDB ID: 38049

Title: Adobe Flash Player HTTP Referer Header CSRF

Info

Disclosure

Jul 10, 2007

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

Flash Player 9.0.45.0 and earlier allow an attacker to manipulate HTTP referrer headers by way of ActionScript. This allows an attacker to spoof the origin of a request and bypass common filters to prevent CSRF. An attacker could leverage this for to issue a CSRF from outside of the target's domain.

Classification

Location: Remote / Network Access
Attack Type: Information Disclosure, Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Unknown
Disclosure: OSVDB Verified, Vendor Verified

Solution

Upgrade to Adobe Flash Player version 9.0.47.0 (Windows) or version 9.0.48.0 (Linux), as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Adobe Systems Incorporated

Flash Player

9.0.45.0

References

Credit

  • Daiki Fukumori - Secure Sky Technology, Inc.


Direct URL: http://osvdb.org/38049