CVE-2007-0044

Adobe Acrobat < 7.0.8 - CSRF

Title source: rule

Description

Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the browser to make unauthorized requests to other web sites via a URL in the (1) FDF, (2) xml, and (3) xfdf AJAX request parameters, following the # (hash) character, aka "Universal CSRF and session riding."

Exploits (1)

exploitdb WORKING POC VERIFIED
by Stefano Di Paola · textremotelinux
https://www.exploit-db.com/exploits/29383

Scores

EPSS 0.3986
EPSS Percentile 97.3%

Classification

CWE
CWE-352
Status draft

Affected Products (36)

adobe/acrobat < 7.0.8
adobe/acrobat
adobe/acrobat
adobe/acrobat
adobe/acrobat
adobe/acrobat
adobe/acrobat
adobe/acrobat
adobe/acrobat
adobe/acrobat
adobe/acrobat
adobe/acrobat
adobe/acrobat
adobe/acrobat
adobe/acrobat
... and 21 more

Timeline

Published Jan 03, 2007
Tracked Since Feb 18, 2026