CVE-2007-0044
Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the browser to make unauthorized requests to other web sites via a URL in the (1) FDF, (2) xml, and (3) xfdf AJAX…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 55.9%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the browser to make unauthorized requests to other web sites via a URL in the (1) FDF, (2) xml, and (3) xfdf AJAX request parameters, following the # (hash) character, aka "Universal CSRF and session riding."
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 55.91% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- adobe/acrobat · adobe/acrobat 3d · adobe/acrobat reader
- Source
- cve@mitre.org
References
- http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf
- http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html
- http://secunia.com/advisories/23812
- http://secunia.com/advisories/23882Vendor Advisory
- http://secunia.com/advisories/29065Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200701-16.xml
- http://securityreason.com/securityalert/2090Vendor Advisory
- http://securitytracker.com/id?1017469
- http://www.redhat.com/support/errata/RHSA-2008-0144.html
- http://www.securityfocus.com/archive/1/455801/100/0/threaded
- http://www.securityfocus.com/bid/21858
- http://www.vupen.com/english/advisories/2007/0032
- http://www.wisec.it/vulns.php?page=9Exploit, Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31266
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10042
- http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf
- http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html
- http://secunia.com/advisories/23812
- http://secunia.com/advisories/23882Vendor Advisory
- http://secunia.com/advisories/29065Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200701-16.xml
- http://securityreason.com/securityalert/2090Vendor Advisory
- http://securitytracker.com/id?1017469
- http://www.redhat.com/support/errata/RHSA-2008-0144.html
- http://www.securityfocus.com/archive/1/455801/100/0/threaded
- http://www.securityfocus.com/bid/21858
- http://www.vupen.com/english/advisories/2007/0032
- http://www.wisec.it/vulns.php?page=9Exploit, Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31266
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10042
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.