[Full-disclosure] Universal XSS with PDF files: highly dangerous

The Anarcat anarcat at anarcat.ath.cx
Mon Jan 8 19:27:12 GMT 2007


Anyone knows how this affects opensource PDF viewers like gpdf or
evince? As I understand this vulnerability, it's only effective
against embeded PDF readers, right?

A.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: Digital signature
Url : http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20070108/cff8f185/attachment.bin 


Full-Disclosure is hosted and sponsored by Secunia.