Multiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, for Mozilla Firefox, Microsoft Internet Explorer 6 SP1, Google Chrome, Opera 8.5.4 build 770, and Opera 9.10.8679 on Windows allow remote attackers to inject arbitrary JavaScript and conduct other attacks via a .pdf URL with a javascript: or res: URI with (1) FDF, (2) XML, and (3) XFDF AJAX parameters, or (4) an arbitrarily named name=URI anchor identifier, aka "Universal XSS (UXSS)."
References
Link Providers
http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf cve-icon cve-icon
http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html cve-icon cve-icon
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742 cve-icon cve-icon
http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html cve-icon cve-icon
http://secunia.com/advisories/23483 cve-icon cve-icon
http://secunia.com/advisories/23691 cve-icon cve-icon
http://secunia.com/advisories/23812 cve-icon cve-icon
http://secunia.com/advisories/23877 cve-icon cve-icon
http://secunia.com/advisories/23882 cve-icon cve-icon
http://secunia.com/advisories/24457 cve-icon cve-icon
http://secunia.com/advisories/24533 cve-icon cve-icon
http://secunia.com/advisories/33754 cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-200701-16.xml cve-icon cve-icon
http://securityreason.com/securityalert/2090 cve-icon cve-icon
http://securitytracker.com/id?1017469 cve-icon cve-icon
http://securitytracker.com/id?1023007 cve-icon cve-icon
http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102847-1 cve-icon cve-icon
http://www.adobe.com/support/security/advisories/apsa07-01.html cve-icon cve-icon
http://www.adobe.com/support/security/advisories/apsa07-02.html cve-icon cve-icon
http://www.adobe.com/support/security/bulletins/apsb07-01.html cve-icon cve-icon
http://www.adobe.com/support/security/bulletins/apsb09-15.html cve-icon cve-icon
http://www.disenchant.ch/blog/hacking-with-browser-plugins/34 cve-icon cve-icon
http://www.gnucitizen.org/blog/danger-danger-danger/ cve-icon cve-icon
http://www.gnucitizen.org/blog/universal-pdf-xss-after-party cve-icon cve-icon
http://www.kb.cert.org/vuls/id/815960 cve-icon cve-icon
http://www.mozilla.org/security/announce/2007/mfsa2007-02.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0021.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/455790/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/455800/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/455801/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/455831/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/455836/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/455906/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/21858 cve-icon cve-icon
http://www.us-cert.gov/cas/techalerts/TA09-286B.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/0032 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/0957 cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/2898 cve-icon cve-icon
http://www.wisec.it/vulns.php?page=9 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/31271 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2007-0045 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6487 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9693 cve-icon cve-icon
https://rhn.redhat.com/errata/RHSA-2007-0017.html cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2007-0045 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2007-01-03T20:00:00

Updated: 2024-08-07T12:03:37.062Z

Reserved: 2007-01-03T00:00:00

Link: CVE-2007-0045

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-01-03T21:28:00.000

Modified: 2018-10-16T16:30:46.040

Link: CVE-2007-0045

cve-icon Redhat

Severity : Important

Publid Date: 2007-01-03T00:00:00Z

Links: CVE-2007-0045 - Bugzilla