Adobe Fixes Flash Authoring XSS Vulnerabilities - InformationWeek
Software // Information Management
04:15 PM
Connect Directly

Adobe Fixes Flash Authoring XSS Vulnerabilities

The security bulletins cover Dreamweaver CS3, Dreamweaver 8, Contribute CS3, Contribute 4, and Connect Enterprise Server.

Adobe has released two security bulletins that address cross-site scripting (XSS) vulnerabilities arising from its media authoring and content serving software.

The security bulletins cover Adobe's Dreamweaver CS3, Dreamweaver 8, Contribute CS3, Contribute 4 and Connect Enterprise Server for Windows and Mac OS.

"Input validation errors have been identified in code generated by Dreamweaver and Contribute which could lead to potential cross-site scripting attacks," Adobe explains in one of its bulletins. "Only customers who have used the Insert Flash Video command in Dreamweaver or Contribute may be vulnerable."

Rich Cannings, a senior information security engineer at Google, described the risks in a public Google Docs file earlier in January, noting that many Web authoring tools insert vulnerable ActionScript code into Flash (.SWF) files. He said that Google hacking queries could reveal hundreds of thousands of vulnerable .SWF files and that "a considerable percentage of major Internet sites are affected."

These files could be used to facilitate cross-site scripting attacks. "If a Web application is vulnerable to XSS, and an attacker lures a user of the vulnerable Web application to click on a link, then the attacker gains complete control of the user's session in the Web application," Cannings explained in his post. "The attacker can use JavaScript to perform any action on behalf of the user (for example, perform a transaction on an online banking system) or change the way the Web site appears to the user (for example, perform a phishing attack)."

XSS vulnerabilities are not uncommon. The site maintains a list of reported XSS holes in Web sites. On Friday, January 18, at the time this article was filed, 10 new vulnerabilities have been reported. The site shows that XSS vulnerabilities have been reported many high-profile domains including,,, and, to name a few. Some of these flaws have been fixed; others apparently remain.

Some security experts consider XSS holes to be less significant than application or network vulnerabilities. But, as security researcher Russ McRee observes, e-commerce sites with XSS issues risk being out of compliance with Payment Card Industry data rules and losing the ability to accept credit cards online.

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
How Enterprises Are Attacking the IT Security Enterprise
How Enterprises Are Attacking the IT Security Enterprise
To learn more about what organizations are doing to tackle attacks and threats we surveyed a group of 300 IT and infosec professionals to find out what their biggest IT security challenges are and what they're doing to defend against today's threats. Download the report to see what they're saying.
Register for InformationWeek Newsletters
White Papers
Current Issue
Digital Transformation Myths & Truths
Transformation is on every IT organization's to-do list, but effectively transforming IT means a major shift in technology as well as business models and culture. In this IT Trend Report, we examine some of the misconceptions of digital transformation and look at steps you can take to succeed technically and culturally.
Twitter Feed
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.
Flash Poll