CVE Database
/

CVE-2007-0045

Back to search

CVE-2007-0045

Published: Jan 3, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, for Mozilla Firefox, Microsoft Internet Explorer 6 SP1, Google Chrome, Opera 8.5.4 build 770, and Opera 9.10.8679 on Windows allow remote attackers to inject arbitrary JavaScript and conduct other attacks via a .pdf URL with a javascript: or res: URI with (1) FDF, (2) XML, and (3) XFDF AJAX parameters, or (4) an arbitrarily named name=URI anchor identifier, aka "Universal XSS (UXSS)."

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2007:0021
vendor-advisory
x_refsource_REDHAT
23691
third-party-advisory
x_refsource_SECUNIA
TA09-286B
third-party-advisory
x_refsource_CERT
RHSA-2007:0017
vendor-advisory
x_refsource_REDHAT
21858
vdb-entry
x_refsource_BID
1023007
vdb-entry
x_refsource_SECTRACK
23882
third-party-advisory
x_refsource_SECUNIA
ADV-2007-0032
vdb-entry
x_refsource_VUPEN
24457
third-party-advisory
x_refsource_SECUNIA
HPSBUX02153
vendor-advisory
x_refsource_HP
adobe-acrobat-pdf-xss(31271)
vdb-entry
x_refsource_XF
2090
third-party-advisory
x_refsource_SREASON
SUSE-SA:2007:011
vendor-advisory
x_refsource_SUSE
102847
vendor-advisory
x_refsource_SUNALERT
33754
third-party-advisory
x_refsource_SECUNIA
ADV-2007-0957
vdb-entry
x_refsource_VUPEN
23812
third-party-advisory
x_refsource_SECUNIA
20070104 Universal PDF XSS After Party
mailing-list
x_refsource_BUGTRAQ
1017469
vdb-entry
x_refsource_SECTRACK
23483
third-party-advisory
x_refsource_SECUNIA
23877
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:9693
vdb-entry
signature
x_refsource_OVAL
oval:org.mitre.oval:def:6487
vdb-entry
signature
x_refsource_OVAL
SSRT061181
vendor-advisory
x_refsource_HP
ADV-2009-2898
vdb-entry
x_refsource_VUPEN
GLSA-200701-16
vendor-advisory
x_refsource_GENTOO
24533
third-party-advisory
x_refsource_SECUNIA
SSA:2007-066-05
vendor-advisory
x_refsource_SLACKWARE
VU#815960
third-party-advisory
x_refsource_CERT-VN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now