CVE-2008-1654

Adobe Flash - CSRF

Title source: llm

Description

Interaction error between Adobe Flash and multiple Universal Plug and Play (UPnP) services allow remote attackers to perform Cross-Site Request Forgery (CSRF) style attacks by using the Flash navigateToURL function to send a SOAP message to a UPnP control point, as demonstrated by changing the primary DNS server.

References (22)

... and 2 more

Scores

EPSS 0.2791
EPSS Percentile 96.4%

Classification

CWE
CWE-352
Status draft

Affected Products (1)

adobe/flash_player

Timeline

Published Apr 02, 2008
Tracked Since Feb 18, 2026