CVE-2006-1627
Last modified
CVE-2006-1627 is a vulnerability of currently unknown severity. Adobe Document Server for Reader Extensions 6.0 does not provide proper access control, which allows remote authenticated users to perform privileged actions by modifying the (1) actionID and (2) pageID parameters. NOTE: due to an error during reservation, this identifier was inadvertently associated with multiple issues. EPSS estimates a 4.27% chance of exploitation in the next 30 days.
Description
Adobe Document Server for Reader Extensions 6.0 does not provide proper access control, which allows remote authenticated users to perform privileged actions by modifying the (1) actionID and (2) pageID parameters. NOTE: due to an error during reservation, this identifier was inadvertently associated with multiple issues. Other CVE identifiers have been assigned to handle other problems that are covered by the same disclosure.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Acrobat Reader | <= 6.0 |
References
- http://secunia.com/advisories/15924Vendor Advisory
- http://secunia.com/secunia_research/2005-68/advisory/Vendor Advisory
- http://secunia.com/advisories/15924Vendor Advisory
- http://secunia.com/secunia_research/2005-68/advisory/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-1627?
How severe is CVE-2006-1627?
How do I fix CVE-2006-1627?
Are you affected by CVE-2006-1627?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
