Executive brief
Macromedia Shockwave is a multimedia platform used to display interactive content in web browsers. A vulnerability in versions prior to 6.0 allows a malicious website to silently read a user's local email files or access internal web servers if the user visits the site. This could result in the theft of private communications, contact lists, and sensitive credentials stored in emails, as well as unauthorized access to private corporate networks.
Technical details
A vulnerability exists in the 'GetNetText' command within Macromedia Shockwave versions prior to 6.0. By predicting the local file path of Netscape Navigator mail folders (e.g., Inbox, Outbox), a malicious Shockwave movie can use the 'mailbox:' protocol to retrieve the contents of these files. The retrieved data can then be exfiltrated to a remote server via HTTP GET requests. Additionally, the command can be used to perform Server-Side Request Forgery (SSRF) style attacks against internal web servers located behind a firewall if the victim is on a corporate network. The issue was addressed in the release of Shockwave 6.0.
Affected products
- Macromedia Shockwave Before 6.0
Timeline
- 1997-03-10: other: Vulnerability reported by David de Vitry
- 1997-03-14: disclosed: Public disclosure via Bugtraq
- 1997-03-14: advisory: NVD publication date
- 1997-03-14: patched: Macromedia confirmed Shockwave 6 fixes the issue