CVE-2005-1306
HIGHAdobe Reader/Acrobat <7.0.1 - Info Disclosure
Title source: llmDescription
The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the "XML External Entity vulnerability."
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Sverre H. Huseby · xmlremotewindows
https://www.exploit-db.com/exploits/25822
Scores
CVSS v3
7.5
EPSS
0.1606
EPSS Percentile
94.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-611
Status
draft
Affected Products (4)
adobe/acrobat
adobe/acrobat
adobe/acrobat_reader
adobe/acrobat_reader
Timeline
Published
Jun 15, 2005
Tracked Since
Feb 18, 2026