标题 简介 类型 公开时间
关联规则 关联知识 关联工具 关联文档 关联抓包
参考1(官网)
参考2
参考3
详情
[SAFE-ID: JIWO-2024-1672]   作者: 特仑苏 发表于: [2018-07-23]

本文共 [436] 位读者顶过

Adobe has patched what researchers describe as a potentially serious security issue in its internal systems, but the company has downplayed the impact of the vulnerability. [出自:jiwo.org]

White hat hackers at Germany-based security research firm Vulnerability Lab claim to have discovered that code submitted through some of Adobe’s event marketing registration forms ultimately made its way to one of the company’s main databases, from where it propagated to emails and web services.

Adobe told SecurityWeek that the issue was a cross-site scripting (XSS) bug in a form used for event marketing registration and said a fix had been implemented. If Adobe’s classification of the flaw is accurate, it was likely a persistent XSS.

Vulnerability Lab told SecurityWeek that it analyzed the issue between November 2017 and February 2018, when it reported its findings to the vendor. The company claims it took until May for Adobe to identify the cause of the problem, with a patch being implemented in mid-June.

Following the disclosure, Adobe included Vulnerability Lab on its industry partners page, which also lists CERT/CC, FireEye, Microsoft, Google, Tencent, Qihoo 360, Kaspersky, Palo Alto Networks and others.

The researchers said there were multiple domains where malicious code could have been inserted and there were multiple places where the code would be executed.

“The code was injected to a micro service, from there it was taken to the main application management service. Then it was synced into the main lead database of Adobe and we had several domains where we were able to place our codes with executable content,” explained Benjamin Kunz Mejri, CEO and founder of Vulnerability Lab.

The exploit code was delivered via emails sent out by Adobe and on some of the company’s domains, Kunz Mejri said.

Attack scheme

Vulnerability Lab has published a blog post and an advisory to describe the vulnerability.

原文链接:https://www.securityweek.com/adobe-patches-vulnerability-affecting-internal-systems

评论

暂无
发表评论
 返回顶部 
热度(436)
 关注微信