First published: Fri Mar 14 1997(Updated: )
Macromedia Shockwave before 6.0 allows a malicious webmaster to read a user's mail box and possibly access internal web servers via the GetNextText command on a Shockwave movie.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Macromedia Shockwave Flash | <=6.0 | |
<=6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1525 has been rated as a high severity vulnerability due to its ability to potentially expose sensitive user information.
To fix CVE-1999-1525, upgrade to a version of Macromedia Shockwave that is greater than 6.0.
CVE-1999-1525 affects Macromedia Shockwave Flash plugin versions up to and including 6.0.
Attackers can exploit CVE-1999-1525 to read users' mailboxes and potentially access internal web servers.
While CVE-1999-1525 is historical, if outdated software is still in use, it can still pose a threat.