First published: Wed Jul 11 2007(Updated: )
Adobe Flash Player 8.0.34.0 and earlier insufficiently validates HTTP Referer headers, which might allow remote attackers to conduct a CSRF attack via a crafted SWF file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Flash Player for Internet Explorer 11 | <=8.0.34.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3457 is rated as a high-severity vulnerability due to its potential to facilitate CSRF attacks.
To fix CVE-2007-3457, upgrade to a later version of Adobe Flash Player beyond 8.0.34.0.
CVE-2007-3457 allows remote attackers to conduct cross-site request forgery (CSRF) attacks.
CVE-2007-3457 affects Adobe Flash Player versions 8.0.34.0 and earlier.
CVE-2007-3457 exploits insufficient validation of HTTP Referer headers to enable unauthorized actions on behalf of users.