CVE-2007-3640
4.3
CVSS SCORE
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
Description
Adobe Integrated Runtime (AIR, aka Apollo) allows context-dependent attackers to modify arbitrary files within an executing .air file (compiled AIR application) and perform cross-site scripting (XSS) attacks, as demonstrated by an application that modifies an HTML file inside itself via JavaScript that uses an APPEND open operation and the writeUTFBytes function. NOTE: this may be an intended consequence of the AIR permission model; if so, then perhaps this issue should not be included in CVE.
CVSS Vector Details
Attack Vector
Network
Attack Complexity
M
Confidentiality
None
Integrity
P
Availability
None
Affected Software Configurations
- a adobe adobe_air * * * * * * * *
Weaknesses (CWE)
- NVD-CWE-Other
References & External Links
- http://osvdb.org/41473
- http://osvdb.org/41474
- http://securityreason.com/securityalert/2882
- http://www.securityfocus.com/archive/1/472733/100/0/threaded
- http://osvdb.org/41473
- http://osvdb.org/41474
- http://securityreason.com/securityalert/2882
- http://www.securityfocus.com/archive/1/472733/100/0/threaded