First published: Thu Apr 13 2006(Updated: )
Adobe Document Server for Reader Extensions 6.0 does not provide proper access control, which allows remote authenticated users to perform privileged actions by modifying the (1) actionID and (2) pageID parameters. NOTE: due to an error during reservation, this identifier was inadvertently associated with multiple issues. Other CVE identifiers have been assigned to handle other problems that are covered by the same disclosure.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | <=6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1627 is classified as a medium severity vulnerability due to improper access controls.
To fix CVE-2006-1627, upgrade Adobe Document Server for Reader Extensions to a version that provides proper access control.
CVE-2006-1627 affects systems running Adobe Acrobat Reader with Reader Extensions version 6.0 and lower.
The potential risks of CVE-2006-1627 include unauthorized access and privilege escalation by authenticated users.
Yes, CVE-2006-1627 can be exploited remotely by authenticated users who can modify specific parameters.