4.3
CVSSv2

CVE-2007-6244

Published: 20/12/2007 Updated: 30/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 440
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player 9.x up to 9.0.48.0 and 8.x up to 8.0.35.0 allow remote malicious users to inject arbitrary web script or HTML via (1) a SWF file that uses the asfunction: protocol or (2) the navigateToURL function when used with the Flash Player ActiveX Control in Internet Explorer.

Vulnerable Product Search on Vulmon Subscribe to Product

adobe flash player 9.0

adobe flash player 8.0

Vendor Advisories

Debian Bug report logs - #459071 CVE-2007-6637: Multiple cross-site scripting (XSS) vulnerabilities Package: flashplugin-nonfree; Maintainer for flashplugin-nonfree is Bart Martens <bartm@debianorg>; Source for flashplugin-nonfree is src:flashplugin-nonfree (PTS, buildd, popcon) Reported by: Steffen Joeris <steffenjoeri ...

Exploits

source: wwwsecurityfocuscom/bid/26960/info The Adobe Flash Player ActiveX control is prone to a cross-domain scripting vulnerability An attacker may leverage this issue to execute arbitrary JavaScript in the context of another domain This issue affects Adobe Flash Player 90480, 80350, and prior versions NOTE: This issue was pr ...
source: wwwsecurityfocuscom/bid/26949/info Adobe Flash Player is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site This may he ...