Macromedia Shockwave before 6.0 allows a malicious webmaster to read a user's mail box and possibly access internal web servers via the GetNextText command on a Shockwave movie.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/1585 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/1586 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/460 | vdb entry |
http://marc.info/?l=bugtraq&m=87602167420670&w=2 | mailing list |