CVE-2007-0044 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 55.9% (pctl 99)
Patch early
A public exploit exists.
Description
Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the browser to make unauthorized requests to other web sites via a URL in the (1) FDF, (2) xml, and (3) xfdf AJAX request parameters, following the # (hash) character, aka "Universal CSRF and session riding."
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 55.91% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-352 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-01-03 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| adobe | acrobat |
| adobe | acrobat 3d |
| adobe | acrobat reader |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Adobe Reader 9.1.3 Plugin - Cross-Site Scripting | 2007-01-03 |
References
- http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf
- http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html
- http://secunia.com/advisories/23812
- http://secunia.com/advisories/23882
- http://secunia.com/advisories/29065
- http://security.gentoo.org/glsa/glsa-200701-16.xml
- http://securityreason.com/securityalert/2090
- http://securitytracker.com/id?1017469
- http://www.redhat.com/support/errata/RHSA-2008-0144.html
- http://www.securityfocus.com/archive/1/455801/100/0/threaded
- http://www.securityfocus.com/bid/21858
- http://www.vupen.com/english/advisories/2007/0032
- http://www.wisec.it/vulns.php?page=9
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31266
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10042
- http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf
- http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html
- http://secunia.com/advisories/23812
- http://secunia.com/advisories/23882
- http://secunia.com/advisories/29065
→ the Explorer · watch your stack · NVD