Interaction error between Adobe Flash and multiple Universal Plug and Play (UPnP) services allow remote attackers to perform Cross-Site Request Forgery (CSRF) style attacks by using the Flash navigateToURL function to send a SOAP message to a UPnP control point, as demonstrated by changing the primary DNS server.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2008-04-02T18:00:00

Updated: 2024-08-07T08:32:01.056Z

Reserved: 2008-04-02T00:00:00

Link: CVE-2008-1654

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2008-04-02T18:44:00.000

Modified: 2017-09-29T01:30:48.550

Link: CVE-2008-1654

cve-icon Redhat

Severity : Moderate

Publid Date: 2008-04-08T00:00:00Z

Links: CVE-2008-1654 - Bugzilla