[Full-disclosure] Universal XSS with PDF files: highly dangerous

Stefano Di Paola stefano.dipaola at wisec.it
Fri Jan 5 16:40:59 GMT 2007


This is in the original advisory.
http://www.wisec.it/vulns.php?page=9

Il giorno ven, 05/01/2007 alle 15.53 +0200, Kristina Lein ha scritto:
> Also I have to tell that my firefox crashed when I appended some random 
> document.write('foobar') to exploit. I suppose it wrote it to PDF memory?! In 
> this case we maybe can also execute code? Scary.
>   Tõnu

Regards 

Stefano

-- 
...oOOo...oOOo....
Stefano Di Paola
Software & Security Engineer

Web: www.wisec.it
..................




Full-Disclosure is hosted and sponsored by Secunia.