Other nomination
Same Origin Bypass in Adobe Reader CVE-2014-8453
Four Adobe Reader flaws presented at HackPra: GoToE and GoToR actions ignore protocol restrictions so a PDF can reach file:// and other local schemes, app.trustPropagatorFunction can be abused to reach privileged JavaScript and read local files, XFA loadXML allows XXE, and FormCalc GET, POST and PUT fetch URLs with the victim's cookies and follow redirects across origins, turning the browser into a proxy and defeating CSRF tokens.
Record
- Published by
- insert-script.blogspot.com
In the archive
Related sources
- Demonstration PDF: JavaScript
- Demonstration PDF: XXE
- Demonstration PDF: XFA
- Privileged JavaScript background slides
Tags
This page is the archive's own catalogue record. The research is the work of insert-script.blogspot.com, first published at the original source. Preserved copies are kept so the citation survives its host.