Input validation error in Shockwave Player - CVE-2012-6270
Published: December 20, 2012 / Updated: August 11, 2020
Shockwave Player
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Adobe Shockwave Player through 11.6.8.638 allows remote attackers to trigger installation of a Shockwave Player 10.4.0.025 compatibility feature via a crafted HTML document that references Shockwave content with a certain compatibility parameter, related to a "downgrading" attack.