>> Adobe Flash Player Clickjacking Security Bypass Vulnerability
Title : Adobe Flash Player Clickjacking Security Bypass Vulnerability VUPEN ID : VUPEN/ADV-2008-2764 CVE ID : CVE-2008-4503
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-10-08
Technical Description
A vulnerability has been identified in Adobe Flash Player, which could be exploited by attackers to bypass security restrictions. This issue is caused by a design error which could allow attackers to e.g. gain access to the system's camera and microphone by luring a web browser user into unknowingly clicking on a link or dialog.
Credits Vulnerability reported by Robert Hansen (SecTheory), Jeremiah Grossman (WhiteHat Security), Eduardo Vela, Matthew Mastracci (DotSpots) and Liu Die Yu.