The library feature for Adobe Content Server 3.0 allows a remote attacker to check out an eBook even when the maximum number of loans is exceeded by accessing the "Add to bookbag" feature when the server reports that no more copies are available.
Link | Tags |
---|---|
http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0020.html | mailing list vendor advisory |
http://marc.info/?l=vuln-dev&m=102650064028760&w=2 | mailing list |
http://marc.info/?l=vuln-dev&m=102649215618643&w=2 | mailing list |