Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the browser to make unauthorized requests to other web sites via a URL in the (1) FDF, (2) xml, and (3) xfdf AJAX request parameters, following the # (hash) character, aka "Universal CSRF and session riding."
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2007-01-03T20:00:00

Updated: 2024-08-07T12:03:36.561Z

Reserved: 2007-01-03T00:00:00

Link: CVE-2007-0044

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-01-03T21:28:00.000

Modified: 2018-10-16T16:30:44.477

Link: CVE-2007-0044

cve-icon Redhat

Severity : Moderate

Publid Date: 2007-01-03T00:00:00Z

Links: CVE-2007-0044 - Bugzilla