Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2007-0045
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-0045

Description:
Multiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, for Mozilla Firefox, Microsoft Internet Explorer 6 SP1, Google Chrome, Opera 8.5.4 build 770, and Opera 9.10.8679 on Windows allow remote attackers to inject arbitrary JavaScript and conduct other attacks via a .pdf URL with a javascript: or res: URI with (1) FDF, (2) XML, and (3) XFDF AJAX parameters, or (4) an arbitrarily named name=URI anchor identifier, aka "Universal XSS (UXSS)."

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/31271

SUSE
  http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html

SUNALERT
  http://sunsolve.sun.com/search/document.do?assetkey=1-26-102847-1

ST
  1023007
  1017469

SREASON
  http://securityreason.com/securityalert/2090

SLACKWARE
  http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131

SAID
  Secunia Advisory: SA23483
  Secunia Advisory: SA23691
  Secunia Advisory: SA23812
  Secunia Advisory: SA23877
  Secunia Advisory: SA23882
  Secunia Advisory: SA24533
  Secunia Advisory: SA24457
  Secunia Advisory: SA33754

REDHAT
  http://www.redhat.com/support/errata/RHSA-2007-0021.html

MISC
  http://www.gnucitizen.org/blog/universal-pdf-xss-after-party
  http://www.disenchant.ch/blog/hacking-with-browser-plugins/34
  http://www.wisec.it/vulns.php?page=9
  http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf

HP
  http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742

GENTOO
  http://security.gentoo.org/glsa/glsa-200701-16.xml

CONFIRM
  http://www.adobe.com/support/security/advisories/apsa07-01.html
  http://www.adobe.com/support/security/advisories/apsa07-02.html
  http://www.adobe.com/support/security/bulletins/apsb07-01.html
  http://www.adobe.com/support/security/bulletins/apsb09-15.html
  http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html
  http://www.gnucitizen.org/blog/danger-danger-danger/
  http://www.mozilla.org/security/announce/2007/mfsa2007-02.html

CERT-VN
  815960

CERT
  http://www.us-cert.gov/cas/techalerts/TA09-286B.html

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/455906/100/0/threaded
  http://www.securityfocus.com/archive/1/455790/100/0/threaded
  http://www.securityfocus.com/archive/1/455831/100/0/threaded
  http://www.securityfocus.com/archive/1/455800/100/0/threaded
  http://www.securityfocus.com/archive/1/455836/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/455801/100/0/threaded

BID
  21858


Return to the previous page.