Document Title:
===============
Adobe Website - Cross Site Scripting Vulnerabilities
References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=371
Release Date:
=============
2012-02-27
Vulnerability Laboratory ID (VL-ID):
====================================
371
Product & Service Introduction:
===============================
Whether it is a smartphone or tablet app, a game, a video, a digital magazine, a website, or an online experience,
chances are that it was touched by Adobe technology. Our tools and services enable our customers to create
groundbreaking digital content, deploy it across media and devices, and then continually measure and optimize it
based on user data. By providing complete solutions that combine digital media creation with data-driven marketing,
we help businesses improve their communications, strengthen their brands, and ultimately achieve greater business success.
(Copy of the Vendor Homepage: http://www.adobe.com/aboutadobe/)
Abstract Advisory Information:
==============================
Vulnerability-Lab Team discovered a non persistent (client side) cross site scripting vulnerability on the Adobe Website.
Vulnerability Disclosure Timeline:
==================================
2011-02-27: Public or Non-Public Disclosure
2011-03-01: Fix/Patch #1
2011-**-**: Fix/Patch #2
Discovery Status:
=================
Published
Exploitation Technique:
=======================
Remote
Severity Level:
===============
Medium
Technical Details & Description:
================================
Multiple non persistent cross site scripting vulnerabilities are detected on the famous Adobe vendor website.
The vulnerability allows an remote attacker with required user inter action to hijack customer sessions via cross site scripting.
Successful exploitation can result in account steal, client side phishing, client side context manipulation or session hijacking.
Vulnerbale Module(s):
[+] Login
[+] Groups Adobe - Search
[+] nocophoto Groups Adobe - Search Author
Picture(s):
../1.png
Proof of Concept (PoC):
=======================
The cross site vulnerabilities can be exploited by remote attackers with required user inter action.
For demonstration or reproduce ...
Note: To reproduce the issue include the script code on the search engine input field.
1.1
PoC:
" NAME="next">
1.2 - 1.3
PoC:
" Author=">"