Adobe Analytics AppMeasurement for Flash Library 跨站脚本漏洞(CVE-2016-1036)发布日期:2016-04-21
更新日期:2016-04-25
受影响系统:Adobe Analytics AppMeasurement for Flash Library < 4.0.1
描述:
CVE(CAN) ID: CVE-2016-1036
FlashPlayer是多媒体程序播放器。
Adobe Analytics AppMeasurement for Flash Library 4.0.1之前版本存在跨站脚本漏洞,启用了debugTracking后,远程攻击者可注入任意Web脚本或HTML。
<*来源:Randy Westergren
链接:https://helpx.adobe.com/security/products/analytics/apsb16-13.html
*>
建议:
厂商补丁:
Adobe
-----
Adobe已经为此发布了一个安全公告(APSB16-13)以及相应补丁:
APSB16-13:Security update available for the Adobe Analytics AppMeasurement for Flash Library
链接:https://helpx.adobe.com/security/products/analytics/apsb16-13.html