Record summary

CVE-2007-6244 has a selected CVSS score of 4.3; EIP currently links 2 catalogued exploits.

Description

Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player 9.x up to 9.0.48.0 and 8.x up to 8.0.35.0 allow remote attackers to inject arbitrary web script or HTML via (1) a SWF file that uses the asfunction: protocol or (2) the navigateToURL function when used with the Flash Player ActiveX Control in Internet Explorer.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBAdobe Flash Player 8.0.34.0/9.0.x - 'main.swf?baseurl' asfunction: Protocol Handler Cross-Site ScriptingExploitDB exploitby Rich CanningsNot analyzed1 file
ExploitDB

PoC details
ExploitDBAdobe Flash Player 7.0.x/8.0.x/9.0.x - ActiveX Control 'navigateToURL' API Cross Domain ScriptingExploitDB exploitby Adam BarthNot analyzed1 file
ExploitDB

PoC details

References

Showing 12 of 23