Vulnerabilities > CVE-2006-1786 - Unspecified vulnerability in Adobe Document Server 6.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Cross-site scripting (XSS) vulnerability in Adobe Document Server for Reader Extensions 6.0 allows remote attackers to inject arbitrary web script or HTML via (1) the actionID parameter in ads-readerext and (2) the op parameter in AlterCast. NOTE: it is not clear whether the vendor advisory addresses this issue.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description Adobe Document Server 6.0 Extensions AlterCast op Parameter XSS. CVE-2006-1786 . Remote exploits for multiple platform id EDB-ID:27637 last seen 2016-02-03 modified 2006-04-13 published 2006-04-13 reporter Tan Chew Keong source https://www.exploit-db.com/download/27637/ title Adobe Document Server 6.0 Extensions AlterCast op Parameter XSS description Adobe Document Server 6.0 Extensions ads-readerext actionID Parameter XSS. CVE-2006-1786. Remote exploits for multiple platform id EDB-ID:27636 last seen 2016-02-03 modified 2006-04-13 published 2006-04-13 reporter Tan Chew Keong source https://www.exploit-db.com/download/27636/ title Adobe Document Server 6.0 Extensions ads-readerext actionID Parameter XSS
Nessus
NASL family | CGI abuses |
NASL id | ADOBE_DOCUMENT_SERVER_61.NASL |
description | The remote host is running Adobe Document Server, a server that dynamically creates and manipulates PDF documents as well as graphic images. The version of Adobe Document Server installed on the remote host includes the Adobe Document Server for Reader Extensions component, which itself is affected by several issues : - Missing Access Controls An authenticated user can gain access to functionality to which they should not have access by manipulating the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 21220 |
published | 2006-04-14 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/21220 |
title | Adobe Document Server for Reader Extensions < 6.1 Multiple Vulnerabilities |
code |
|
References
- http://secunia.com/secunia_research/2005-68/advisory/
- http://www.adobe.com/support/techdocs/322699.html
- http://secunia.com/advisories/15924
- http://www.securityfocus.com/bid/17500
- http://www.osvdb.org/24590
- http://www.osvdb.org/24589
- http://www.vupen.com/english/advisories/2006/1342
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25771
- http://www.securityfocus.com/archive/1/430869/100/0/threaded