Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player 9.x up to 9.0.48.0 and 8.x up to 8.0.35.0 allow remote attackers to inject arbitrary web script or HTML via (1) a SWF file that uses the asfunction: protocol or (2) the navigateToURL function when used with the Flash Player ActiveX Control in Internet Explorer.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Adobe Flash Player navigateToURL跨站脚本漏洞漏洞
Vulnerability Description
Flash Player是一款非常流行的FLASH播放器。 Flash Player ActiveX控件处理SWF的内嵌数据时存在漏洞,远程攻击者可能利用此漏洞诱使用户访问恶意网站。 Flash Player ActiveX控件在处理navigateToURL API时用到了两个参数:URL和将要导航到帧的名称。SWF电影可能传送其他域的JavaScript: URI和帧的名称,这样就可以在命名帧的安全环境而不是SWF电影或内嵌Flash网页的安全环境执行URL中的代码。
CVSS Information
N/A
Vulnerability Type
N/A