CVE-2008-1654
02.04.2008, 18:44
Interaction error between Adobe Flash and multiple Universal Plug and Play (UPnP) services allow remote attackers to perform Cross-Site Request Forgery (CSRF) style attacks by using the Flash navigateToURL function to send a SOAP message to a UPnP control point, as demonstrated by changing the primary DNS server.
Vendor | Product | Version |
---|---|---|
adobe | flash_player | * |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References