Cross-Site Scripting Vulnerability in Adobe Document Server for Reader Extensions
CVE-2006-1786
Currently unrated
Summary
A Cross-Site Scripting (XSS) vulnerability exists in Adobe Document Server for Reader Extensions, specifically in version 6.0. This flaw allows remote attackers to inject arbitrary web scripts or HTML through the 'actionID' parameter in the ads-readerext component and the 'op' parameter in AlterCast. The specific handling of these parameters can lead to unauthorized script execution in the context of the victim’s session, potentially compromising user data and security. It's important to note that the vendor's advisory may not fully address the implications of this issue.
References
Timeline
Vulnerability published
Vulnerability Reserved