peter bassill · operator
$ cve CVE-2007-0044 JSON

CVE-2007-0044 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 55.9% (pctl 99)

Patch early

A public exploit exists.

Description

Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the browser to make unauthorized requests to other web sites via a URL in the (1) FDF, (2) xml, and (3) xfdf AJAX request parameters, following the # (hash) character, aka "Universal CSRF and session riding."

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS55.91% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2007-01-03
Last modified2026-06-16

Affected (3)

VendorProduct
adobeacrobat
adobeacrobat 3d
adobeacrobat reader

Public exploits

SourceTitleDate
exploit-dbAdobe Reader 9.1.3 Plugin - Cross-Site Scripting2007-01-03

References

→ the Explorer  ·  watch your stack  ·  NVD