CVE-2008-1654
Adobe Flash - CSRF
Title source: llmDescription
Interaction error between Adobe Flash and multiple Universal Plug and Play (UPnP) services allow remote attackers to perform Cross-Site Request Forgery (CSRF) style attacks by using the Flash navigateToURL function to send a SOAP message to a UPnP control point, as demonstrated by changing the primary DNS server.
References (22)
... and 2 more
Scores
EPSS
0.2791
EPSS Percentile
96.4%
Classification
CWE
CWE-352
Status
draft
Affected Products (1)
adobe/flash_player
Timeline
Published
Apr 02, 2008
Tracked Since
Feb 18, 2026