Document Title: =============== Adobe Website - Cross Site Scripting Vulnerabilities References (Source): ==================== http://www.vulnerability-lab.com/get_content.php?id=371 Release Date: ============= 2012-02-27 Vulnerability Laboratory ID (VL-ID): ==================================== 371 Product & Service Introduction: =============================== Whether it is a smartphone or tablet app, a game, a video, a digital magazine, a website, or an online experience, chances are that it was touched by Adobe technology. Our tools and services enable our customers to create groundbreaking digital content, deploy it across media and devices, and then continually measure and optimize it based on user data. By providing complete solutions that combine digital media creation with data-driven marketing, we help businesses improve their communications, strengthen their brands, and ultimately achieve greater business success. (Copy of the Vendor Homepage: http://www.adobe.com/aboutadobe/) Abstract Advisory Information: ============================== Vulnerability-Lab Team discovered a non persistent (client side) cross site scripting vulnerability on the Adobe Website. Vulnerability Disclosure Timeline: ================================== 2011-02-27: Public or Non-Public Disclosure 2011-03-01: Fix/Patch #1 2011-**-**: Fix/Patch #2 Discovery Status: ================= Published Exploitation Technique: ======================= Remote Severity Level: =============== Medium Technical Details & Description: ================================ Multiple non persistent cross site scripting vulnerabilities are detected on the famous Adobe vendor website. The vulnerability allows an remote attacker with required user inter action to hijack customer sessions via cross site scripting. Successful exploitation can result in account steal, client side phishing, client side context manipulation or session hijacking. Vulnerbale Module(s): [+] Login [+] Groups Adobe - Search [+] nocophoto Groups Adobe - Search Author Picture(s): ../1.png Proof of Concept (PoC): ======================= The cross site vulnerabilities can be exploited by remote attackers with required user inter action. For demonstration or reproduce ... Note: To reproduce the issue include the script code on the search engine input field. 1.1 PoC: " NAME="next"> 1.2 - 1.3 PoC: " Author=">"