CVE-2007-0044
Adobe Acrobat Reader Plugin < 8.0.0 - Cross-Site Request Forgery via FDF/XML/XFDF AJAX Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0044. PoCs published by Stefano Di Paola.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Adobe Reader Plugin versions 6 and 7. The PoC uses a maliciously crafted PDF URL to execute arbitrary JavaScript in the context of the visited site, potentially stealing authentication credentials.
Description
Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the browser to make unauthorized requests to other web sites via a URL in the (1) FDF, (2) xml, and (3) xfdf AJAX request parameters, following the # (hash) character, aka "Universal CSRF and session riding."
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Adobe Reader Plugin versions 6 and 7. The PoC uses a maliciously crafted PDF URL to execute arbitrary JavaScript in the context of the visited site, potentially stealing authentication credentials.