Posted by houjingyi on Jan 29

Last year I did some research on JavaScript API used in PDF reader. I found
that if you provide a path to submitForm then this path will be created by
Foxit PDF reader when opening the PDF, this is an *Arbitrary File Write*.

Unfortunately I did not find a way to control the content of the
file…..If you can control the content of the file then you can get *100%
stable RCE*!

This issue was fixed in Foxit PhantomPDF 10.1.5(…
Read More – Full Disclosure

By |2022-01-29T15:18:51-05:00January 29th, 2022|