[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2007-0045Date: (C)2007-01-03   (M)2023-12-22


Multiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, for Mozilla Firefox, Microsoft Internet Explorer 6 SP1, Google Chrome, Opera 8.5.4 build 770, and Opera 9.10.8679 on Windows allow remote attackers to inject arbitrary JavaScript and conduct other attacks via a .pdf URL with a javascript: or res: URI with (1) FDF, (2) XML, and (3) XFDF AJAX parameters, or (4) an arbitrarily named name=URI anchor identifier, aka "Universal XSS (UXSS)."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.3
Exploit Score: 8.6
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
SECTRACK-1017469
SECTRACK-1023007
SUNALERT-102847
http://www.securityfocus.com/archive/1/455801/100/0/threaded
http://www.securityfocus.com/archive/1/455836/100/0/threaded
http://www.securityfocus.com/archive/1/455800/100/0/threaded
http://www.securityfocus.com/archive/1/455831/100/0/threaded
http://www.securityfocus.com/archive/1/455790/100/0/threaded
http://www.securityfocus.com/archive/1/455906/100/0/threaded
SREASON-2090
BID-21858
SECUNIA-23483
SECUNIA-23691
SECUNIA-23812
SECUNIA-23877
SECUNIA-23882
SECUNIA-24457
SECUNIA-24533
SECUNIA-33754
ADV-2007-0032
ADV-2007-0957
ADV-2009-2898
GLSA-200701-16
HPSBUX02153
RHSA-2007:0017
RHSA-2007:0021
SSA:2007-066-05
SUSE-SA:2007:011
TA09-286B
VU#815960
adobe-acrobat-pdf-xss(31271)
http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf
http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html
http://www.adobe.com/support/security/advisories/apsa07-01.html
http://www.adobe.com/support/security/advisories/apsa07-02.html
http://www.adobe.com/support/security/bulletins/apsb07-01.html
http://www.adobe.com/support/security/bulletins/apsb09-15.html
http://www.disenchant.ch/blog/hacking-with-browser-plugins/34
http://www.gnucitizen.org/blog/danger-danger-danger/
http://www.gnucitizen.org/blog/universal-pdf-xss-after-party
http://www.mozilla.org/security/announce/2007/mfsa2007-02.html
http://www.wisec.it/vulns.php?page=9
oval:org.mitre.oval:def:6487
oval:org.mitre.oval:def:9693

CPE    17
cpe:/a:adobe:acrobat_reader:6.0
cpe:/a:adobe:acrobat_reader:6.0.2
cpe:/a:adobe:acrobat_reader:6.0.1
cpe:/a:adobe:acrobat_reader:7.0
...
CWE    1
CWE-79
OVAL    6
oval:org.secpod.oval:def:36780
oval:org.secpod.oval:def:18653
oval:org.secpod.oval:def:400086
oval:org.secpod.oval:def:18679
...

© SecPod Technologies