CVE-2007-0044

Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the browser to make unauthorized requests to other web sites via a URL in the (1) FDF, (2) xml, and (3) xfdf AJAX request parameters, following the # (hash) character, aka "Universal CSRF and session riding."
References
Link Resource
http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf
http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html
http://secunia.com/advisories/23812
http://secunia.com/advisories/23882 Vendor Advisory
http://secunia.com/advisories/29065 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200701-16.xml
http://securityreason.com/securityalert/2090 Vendor Advisory
http://securitytracker.com/id?1017469
http://www.redhat.com/support/errata/RHSA-2008-0144.html
http://www.securityfocus.com/archive/1/455801/100/0/threaded
http://www.securityfocus.com/bid/21858
http://www.vupen.com/english/advisories/2007/0032
http://www.wisec.it/vulns.php?page=9 Exploit Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/31266
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10042
http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf
http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html
http://secunia.com/advisories/23812
http://secunia.com/advisories/23882 Vendor Advisory
http://secunia.com/advisories/29065 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200701-16.xml
http://securityreason.com/securityalert/2090 Vendor Advisory
http://securitytracker.com/id?1017469
http://www.redhat.com/support/errata/RHSA-2008-0144.html
http://www.securityfocus.com/archive/1/455801/100/0/threaded
http://www.securityfocus.com/bid/21858
http://www.vupen.com/english/advisories/2007/0032
http://www.wisec.it/vulns.php?page=9 Exploit Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/31266
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10042
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:adobe:acrobat:*:*:elements:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:7.0:*:professional:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:7.0:*:standard:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:7.0.1:*:professional:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:7.0.1:*:standard:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:7.0.2:*:professional:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:7.0.2:*:standard:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:7.0.3:*:professional:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:7.0.3:*:standard:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:7.0.4:*:professional:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:7.0.4:*:standard:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:7.0.5:*:professional:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:7.0.5:*:standard:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:7.0.6:*:professional:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:7.0.6:*:standard:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:7.0.7:*:professional:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:7.0.7:*:standard:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:7.0.8:*:professional:*:*:*:*:*
cpe:2.3:a:adobe:acrobat:7.0.8:*:standard:*:*:*:*:*
cpe:2.3:a:adobe:acrobat_3d:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat_reader:6.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat_reader:6.0.1:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat_reader:6.0.2:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat_reader:6.0.3:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat_reader:6.0.4:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat_reader:6.0.5:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat_reader:7.0:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat_reader:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat_reader:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat_reader:7.0.3:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat_reader:7.0.4:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat_reader:7.0.5:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat_reader:7.0.6:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat_reader:7.0.7:*:*:*:*:*:*:*
cpe:2.3:a:adobe:acrobat_reader:7.0.8:*:*:*:*:*:*:*

History

21 Nov 2024, 00:24

Type Values Removed Values Added
References () http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf - () http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf -
References () http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html - () http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html -
References () http://secunia.com/advisories/23812 - () http://secunia.com/advisories/23812 -
References () http://secunia.com/advisories/23882 - Vendor Advisory () http://secunia.com/advisories/23882 - Vendor Advisory
References () http://secunia.com/advisories/29065 - Vendor Advisory () http://secunia.com/advisories/29065 - Vendor Advisory
References () http://security.gentoo.org/glsa/glsa-200701-16.xml - () http://security.gentoo.org/glsa/glsa-200701-16.xml -
References () http://securityreason.com/securityalert/2090 - Vendor Advisory () http://securityreason.com/securityalert/2090 - Vendor Advisory
References () http://securitytracker.com/id?1017469 - () http://securitytracker.com/id?1017469 -
References () http://www.redhat.com/support/errata/RHSA-2008-0144.html - () http://www.redhat.com/support/errata/RHSA-2008-0144.html -
References () http://www.securityfocus.com/archive/1/455801/100/0/threaded - () http://www.securityfocus.com/archive/1/455801/100/0/threaded -
References () http://www.securityfocus.com/bid/21858 - () http://www.securityfocus.com/bid/21858 -
References () http://www.vupen.com/english/advisories/2007/0032 - () http://www.vupen.com/english/advisories/2007/0032 -
References () http://www.wisec.it/vulns.php?page=9 - Exploit, Patch () http://www.wisec.it/vulns.php?page=9 - Exploit, Patch
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/31266 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/31266 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10042 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10042 -

Information

Published : 2007-01-03 21:28

Updated : 2024-11-21 00:24


NVD link : CVE-2007-0044

Mitre link : CVE-2007-0044

CVE.ORG link : CVE-2007-0044


JSON object : View

Products Affected

adobe

  • acrobat_reader
  • acrobat
  • acrobat_3d
CWE
CWE-352

Cross-Site Request Forgery (CSRF)