7.5
CVSSv2

CVE-2007-0046

Published: 03/01/2007 Updated: 16/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Double free vulnerability in the Adobe Acrobat Reader Plugin prior to 8.0.0, as used in Mozilla Firefox 1.5.0.7, allows remote malicious users to execute arbitrary code by causing an error via a javascript: URI call to document.write in the (1) FDF, (2) XML, or (3) XFDF AJAX request parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

adobe acrobat reader

Exploits

# Stefano Di Paola # wwwwisecit/ From Secunia: Input passed to a hosted PDF file is not properly sanitised by the browser plug-in before being returned to users This can be exploited to execute arbitrary script code in a user's browser session in context of an affected site Example: - [host]/[filename]pdf#[some text]=javascript ...