Adobe Document Server for Reader Extensions 6.0 includes a user's session (jsession) ID in the HTTP Referer header, which allows remote malicious users to gain access to PDF files that are being processed within that session.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
adobe document server 6.0 |