Flash Player HTTP Header CRLF Injection (APSB06-18)

Medium Nessus Plugin ID 23869


The remote Windows host contains a browser plugin that is affected by multiple HTTP header injection issues.


According to its version number, the instance of Flash Player on the remote Windows host contains two ways for a remote attacker to perform arbitrary HTTP requests while controlling most of the HTTP headers. A remote attacker may be able to leverage these issues to conduct cross-site request forgery attacks against a user who visits a malicious website.


Upgrade to Flash Player version / / or later.

See Also



Plugin Details

Severity: Medium

ID: 23869

File Name: flash_player_apsb06-18.nasl

Version: $Revision: 1.15 $

Type: local

Agent: windows

Family: Windows

Published: 2006/12/15

Modified: 2017/01/06

Dependencies: 28211

Risk Information

Risk Factor: Medium


Base Score: 5

Temporal Score: 4.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Temporal Vector: CVSS2#E:F/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:adobe:flash_player

Required KB Items: SMB/Flash_Player/installed

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2006/11/14

Vulnerability Publication Date: 2006/10/17

Reference Information

CVE: CVE-2006-5330

BID: 20592, 20593

OSVDB: 29863

CWE: 79