activex

1 article
sort: new top best
clear filter
0 7/10
vulnerability

A DOM XSS vulnerability in Adobe's PDF ActiveX plugin (res://apds.dll/redirect.html) can be exploited via IE by using the xfa.host.gotoURL() function to bypass same-origin policy restrictions and execute arbitrary JavaScript without security warnings. The vulnerability chains a parameter injection flaw with Adobe's insecure URL redirect handling to achieve cross-domain XSS.

CVE-2019-8160 APSB19-49 Adobe PSIRT MSRC KnownSec 404 Team Heige apds.dll
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details