• Announcements

    • gbarry

      Reach out to Evernote support on Twitter @EvernoteHelps   09/20/2016

      We've been leveling up our support across all channels. If you're active on Twitter, try your hand with our @evernotehelps feed. It's helmed by a crack team out of Austin, TX who are here to answer your questions. They're generally active from 7am-4pm CST.  https://twitter.com/evernotehelps  
Sign in to follow this  
SFdude

windows (Archived) Evernote PDF Reader from Foxit - security concern?

Recommended Posts

SFdude    1

Using EV client version 3.1.0,1225

(yes, I know - it's ancient, but it works for me...),

with WIN-XP SP3 -32 bit.

 

When I read a PDF stored as an EV Note,

EV pops up an info window,

saying it's using the FOXIT PDF Reader inside EV,

to render the PDF.

That's OK...

 

But what if the PDF (stored and rendered inside EV),

contains an embeded, malicious JS script,

and the JS script gets executed

by the EV Foxit Reader?

 

For my local PDF files (in my HD),

I read them with Sumatra PDF Reader or PDF-Xchange Reader,

both with JS script execution TURNED OFF...

 

So....the Question:

==============

 

Does EVs Foxit Reader have JS script execution TURNED OFF?

(while rendering a PDF file INSIDE the EV client version 3.1.0,1225).

 

If it is not turned off,

that would be a HUGE security risk in PDF rendering in EV.!

 

Thanks.

Share this post


Link to post
Guest
This topic is now closed to further replies.
Sign in to follow this