First published: Wed Jan 03 2007(Updated: )
Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the browser to make unauthorized requests to other web sites via a URL in the (1) FDF, (2) xml, and (3) xfdf AJAX request parameters, following the # (hash) character, aka "Universal CSRF and session riding."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | =7.0.6 | |
Adobe Acrobat Reader | =7.0.5 | |
Adobe Acrobat Reader | =7.0.6 | |
Adobe Acrobat Reader | =7.0 | |
Adobe Acrobat Reader | =7.0 | |
Adobe Acrobat Reader | =7.0.8 | |
Adobe Acrobat Reader | =7.0.5 | |
Adobe Acrobat Reader | =6.0.3 | |
Adobe Acrobat Reader | <=7.0.8 | |
Adobe Acrobat 3d | ||
Adobe Acrobat Reader | =7.0.7 | |
Adobe Acrobat Reader | =7.0.3 | |
Adobe Acrobat Reader | =7.0.4 | |
Adobe Acrobat Reader | =7.0.6 | |
Adobe Acrobat Reader | =7.0.5 | |
Adobe Acrobat Reader | =7.0.3 | |
Adobe Acrobat Reader | =7.0.2 | |
Adobe Acrobat Reader | =7.0.1 | |
Adobe Acrobat Reader | =7.0.2 | |
Adobe Acrobat Reader | =7.0 | |
Adobe Acrobat Reader | =7.0.7 | |
Adobe Acrobat Reader | =7.0.8 | |
Adobe Acrobat Reader | =7.0.1 | |
Adobe Acrobat Reader | =6.0.1 | |
Adobe Acrobat Reader | =6.0.5 | |
Adobe Acrobat Reader | =7.0.7 | |
Adobe Acrobat Reader | =7.0.4 | |
Adobe Acrobat Reader | =7.0.8 | |
Adobe Acrobat Reader | =7.0.2 | |
Adobe Acrobat Reader | =6.0 | |
Adobe Acrobat Reader | =6.0.2 | |
Adobe Acrobat Reader | =7.0.3 | |
Adobe Acrobat Reader | =6.0.4 | |
Adobe Acrobat Reader | <=7.0.8 | |
Adobe Acrobat Reader | =7.0.4 | |
Adobe Acrobat Reader | =7.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0044 is considered a moderate severity vulnerability that can allow unauthorized requests via AJAX parameters.
To fix CVE-2007-0044, upgrade to Adobe Acrobat Reader version 8.0.0 or later.
CVE-2007-0044 affects multiple versions of Adobe Acrobat and Adobe Acrobat Reader, specifically versions prior to 8.0.0.
Yes, CVE-2007-0044 can potentially lead to data theft as it allows attackers to send unauthorized requests to other websites.
Yes, CVE-2007-0044 can be exploited remotely by attackers targeting vulnerable Adobe Acrobat Reader installations.