Adobe Document Server for Reader Extensions < 6.1 Multiple Vulnerabilities

high Nessus Plugin ID 21220

Synopsis

The remote web server is affected by multiple flaws.

Description

The remote host is running Adobe Document Server, a server that dynamically creates and manipulates PDF documents as well as graphic images.

The version of Adobe Document Server installed on the remote host includes the Adobe Document Server for Reader Extensions component, which itself is affected by several issues :

- Missing Access Controls An authenticated user can gain access to functionality to which they should not have access by manipulating the 'actionID' and 'pageID' parameters.

- Cross-Site Scripting Flaws The application fails to sanitize input to several parameters before using it to generate dynamic web content.

- Information Disclosure The application exposes a user's session id in the Referer header, which can lead to a loss of confidentiality. Also, the application returns different error messages during unsuccessful authentication attempts, which can be used to enumerate users.

Solution

Upgrade to Adobe Document Server for Reader Extensions 6.1 / LiveCycle Reader Extensions 7.0 or later.

See Also

https://secuniaresearch.flexerasoftware.com/secunia_research/2005-68/advisory/

http://www.nessus.org/u?81de277d

http://www.nessus.org/u?e25b3734

http://www.nessus.org/u?af7f3dbb

Plugin Details

Severity: High

ID: 21220

File Name: adobe_document_server_61.nasl

Version: 1.28

Type: remote

Family: CGI abuses

Published: 4/14/2006

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.3

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 7.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/a:adobe:document_server

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/11/2006

Vulnerability Publication Date: 4/13/2006

Reference Information

CVE: CVE-2006-1627, CVE-2006-1785, CVE-2006-1786, CVE-2006-1787, CVE-2006-1788

BID: 17500

CWE: 20, 442, 629, 711, 712, 722, 725, 74, 750, 751, 79, 800, 801, 809, 811, 864, 900, 928, 931, 990