Vulnerability record · CVE-2007-0044 · published 3 January 2007
CVE-2007-0044: Adobe Acrobat Reader Plugin browser request forgery via AJAX parameters
Adobe · Acrobat
Adobe Acrobat Reader Plugin before 8.0.0 for Firefox, Internet Explorer and Opera lets remote attackers force the browser to make unauthorized requests to other web sites by placing a URL in the FDF, xml, or xfdf AJAX request parameters after the # character. This is a cross-site request forgery and session-riding flaw, so a page the victim visits can silently drive the browser to act against other sites using the victim's credentials.
Description
Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the browser to make unauthorized requests to other web sites via a URL in the (1) FDF, (2) xml, and (3) xfdf AJAX request parameters, following the # (hash) character, aka "Universal CSRF and session riding."
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityThe flaw is a medium-severity CSRF with integrity-only impact and requires user interaction, though public exploit material and a high EPSS score raise concern.
What it is
Adobe Acrobat Reader Plugin before 8.0.0 for Firefox, Internet Explorer and Opera lets remote attackers force the browser to make unauthorized requests to other web sites by placing a URL in the FDF, xml, or xfdf AJAX request parameters after the # character. This is a cross-site request forgery and session-riding flaw, so a page the victim visits can silently drive the browser to act against other sites using the victim's credentials.
Impact
An attacker can make the victim's browser issue unauthorized requests to arbitrary sites, riding the victim's authenticated session to perform state-changing actions. The CVSS 2.0 vector rates integrity impact only (I:P), with no confidentiality or availability impact.
Attack surface
Reached over the network through a crafted web page or PDF that supplies a URL in the FDF, xml, or xfdf AJAX parameters after the # character; the browser plugin processes it. No authentication is required (Au:N), but the victim must visit the malicious content, so user interaction is needed.
Exploitation
Not listed in CISA KEV and no ransomware use is documented. EPSS is high (0.55909, 98.997th percentile), and one reference is tagged Exploit and Patch, indicating public exploit material exists.
What to do
- Upgrade Adobe Acrobat Reader Plugin to 8.0.0 or later, or apply the vendor patch referenced in the advisory.
- Apply the distribution updates from Red Hat, SUSE and Gentoo advisories where the plugin is packaged.
- Disable or remove the browser PDF plugin and open PDFs in a standalone reader to cut the browser attack path.
- Restrict the plugin from loading untrusted PDF or FDF content and block untrusted sites from triggering plugin requests.
- Treat cross-site requests from PDF plugin sessions as untrusted and require re-authentication for sensitive actions.
Detection
- Monitor browser and proxy logs for requests to unexpected external sites originating from PDF plugin activity.
- Look for FDF, xml, or xfdf parameter values containing a URL after a # character in web or plugin request logs.
- Alert on cross-site requests that carry session cookies but lack a normal user navigation referer.
- Review endpoint logs for Acrobat Reader Plugin versions below 8.0.0 on hosts with Firefox, Internet Explorer or Opera.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-0044 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-0044), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.