PT-2006-2199 · Adobe · Document Server+2
Tan Chew Keong
·
Published
2006-03-16
·
Updated
2018-10-18
·
CVE-2006-1182
CVSS v2.0
2.6
Low
| Vector | AV:L/AC:H/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Adobe Graphics Server versions 2.0 through 2.1
Adobe Document Server versions 5.0 through 6.0
Description
The issue allows local users to read files with certain extensions or overwrite arbitrary files and execute code via a crafted SOAP request to the AlterCast web service. This can be achieved by using specific commands such as
saveContent, saveOptimized, or loadContent in the request.Recommendations
For Adobe Graphics Server versions 2.0 through 2.1, consider restricting access to the AlterCast web service until a fix is available.
For Adobe Document Server versions 5.0 through 6.0, avoid using the
saveContent, saveOptimized, or loadContent commands in the SOAP request until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Document Server
Graphics Server
Altercast Web Service