First published: Thu Dec 20 2007(Updated: )
Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0 does not sufficiently restrict the interpretation and usage of cross-domain policy files, which makes it easier for remote attackers to conduct cross-domain and cross-site scripting (XSS) attacks.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Flash Player for Internet Explorer 11 | <=9.0.48.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6243 has a medium severity rating due to its potential for enabling cross-domain and cross-site scripting attacks.
To fix CVE-2007-6243, update Adobe Flash Player to version 9.0.48.0 or later, or upgrade to a newer version if available.
CVE-2007-6243 affects Adobe Flash Player versions 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0.
CVE-2007-6243 can be exploited for cross-domain and cross-site scripting (XSS) attacks, making it a security concern.
While CVE-2007-6243 is an older vulnerability, systems that still run the affected versions of Adobe Flash Player remain at risk unless properly updated.