CVE-2007-0044: CSRF
Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the browser to make unauthorized requests to other web sites via a URL in the (1) FDF, (2) xml, and (3) xfdf AJAX request parameters, following the # (hash) character, aka "Universal CSRF and session riding."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0044?
CVE-2007-0044 is considered a moderate severity vulnerability that can allow unauthorized requests via AJAX parameters.
How do I fix CVE-2007-0044?
To fix CVE-2007-0044, upgrade to Adobe Acrobat Reader version 8.0.0 or later.
What products are affected by CVE-2007-0044?
CVE-2007-0044 affects multiple versions of Adobe Acrobat and Adobe Acrobat Reader, specifically versions prior to 8.0.0.
Can CVE-2007-0044 lead to data theft?
Yes, CVE-2007-0044 can potentially lead to data theft as it allows attackers to send unauthorized requests to other websites.
Is CVE-2007-0044 exploitable remotely?
Yes, CVE-2007-0044 can be exploited remotely by attackers targeting vulnerable Adobe Acrobat Reader installations.