Skip to content
Saturday, December 6, 2025
Medium Published: Jan 03, 2007 Modified: Apr 09, 2025

CVE-2007-0044

4.3 CVSS SCORE
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
Share:

Description

Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the browser to make unauthorized requests to other web sites via a URL in the (1) FDF, (2) xml, and (3) xfdf AJAX request parameters, following the # (hash) character, aka "Universal CSRF and session riding."

CVSS Vector Details

Attack Vector Network
Attack Complexity M
Confidentiality None
Integrity P
Availability None

Affected Software Configurations

  • a adobe acrobat * * elements * * * * *
  • a adobe acrobat 7.0 * professional * * * * *
  • a adobe acrobat 7.0 * standard * * * * *
  • a adobe acrobat 7.0.1 * professional * * * * *
  • a adobe acrobat 7.0.1 * standard * * * * *
  • a adobe acrobat 7.0.2 * professional * * * * *
  • a adobe acrobat 7.0.2 * standard * * * * *
  • a adobe acrobat 7.0.3 * professional * * * * *
  • a adobe acrobat 7.0.3 * standard * * * * *
  • a adobe acrobat 7.0.4 * professional * * * * *

Weaknesses (CWE)

  • CWE-352

References & External Links