Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-1654

Опубликовано: 02 апр. 2008
Источник: nvd
CVSS2: 4.3
EPSS Средний

Описание

Interaction error between Adobe Flash and multiple Universal Plug and Play (UPnP) services allow remote attackers to perform Cross-Site Request Forgery (CSRF) style attacks by using the Flash navigateToURL function to send a SOAP message to a UPnP control point, as demonstrated by changing the primary DNS server.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*

EPSS

Процентиль: 97%
0.30802
Средний

4.3 Medium

CVSS2

Дефекты

CWE-352

Связанные уязвимости

ubuntu
больше 17 лет назад

Interaction error between Adobe Flash and multiple Universal Plug and Play (UPnP) services allow remote attackers to perform Cross-Site Request Forgery (CSRF) style attacks by using the Flash navigateToURL function to send a SOAP message to a UPnP control point, as demonstrated by changing the primary DNS server.

redhat
больше 17 лет назад

Interaction error between Adobe Flash and multiple Universal Plug and Play (UPnP) services allow remote attackers to perform Cross-Site Request Forgery (CSRF) style attacks by using the Flash navigateToURL function to send a SOAP message to a UPnP control point, as demonstrated by changing the primary DNS server.

debian
больше 17 лет назад

Interaction error between Adobe Flash and multiple Universal Plug and ...

github
больше 3 лет назад

Interaction error between Adobe Flash and multiple Universal Plug and Play (UPnP) services allow remote attackers to perform Cross-Site Request Forgery (CSRF) style attacks by using the Flash navigateToURL function to send a SOAP message to a UPnP control point, as demonstrated by changing the primary DNS server.

EPSS

Процентиль: 97%
0.30802
Средний

4.3 Medium

CVSS2

Дефекты

CWE-352