Cross-Site Scripting Vulnerability in Adobe Document Server for Reader Extensions
CVE-2006-1786

Currently unrated

Key Information:

Vendor

Adobe

Vendor
CVE Published:
13 April 2006

What is CVE-2006-1786?

A Cross-Site Scripting (XSS) vulnerability exists in Adobe Document Server for Reader Extensions, specifically in version 6.0. This flaw allows remote attackers to inject arbitrary web scripts or HTML through the 'actionID' parameter in the ads-readerext component and the 'op' parameter in AlterCast. The specific handling of these parameters can lead to unauthorized script execution in the context of the victim’s session, potentially compromising user data and security. It's important to note that the vendor's advisory may not fully address the implications of this issue.

References

EPSS Score

5% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.