The library feature for Adobe Content Server 3.0 allows a remote attacker to check out an eBook for an arbitrary length of time via a modified loanMin parameter to download.asp.
Link | Tags |
---|---|
http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0020.html | mailing list vendor advisory |
http://marc.info/?l=vuln-dev&m=102650064028760&w=2 | mailing list |
http://marc.info/?l=vuln-dev&m=102649215618643&w=2 | mailing list |