← Vulnerability feed

Vulnerability record · CVE-2007-0044 · published 3 January 2007

CVE-2007-0044: Adobe Acrobat Reader Plugin browser request forgery via AJAX parameters

Adobe · Acrobat

Adobe Acrobat Reader Plugin before 8.0.0 for Firefox, Internet Explorer and Opera lets remote attackers force the browser to make unauthorized requests to other web sites by placing a URL in the FDF, xml, or xfdf AJAX request parameters after the # character. This is a cross-site request forgery and session-riding flaw, so a page the victim visits can silently drive the browser to act against other sites using the victim's credentials.

4.3 CVSS 2.0 Medium EPSS 56% · top 1.0% CWE-352 · Cross-site request forgery
4.3CVSS 2.0 base score
56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
30References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the browser to make unauthorized requests to other web sites via a URL in the (1) FDF, (2) xml, and (3) xfdf AJAX request parameters, following the # (hash) character, aka "Universal CSRF and session riding."

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

medium priorityThe flaw is a medium-severity CSRF with integrity-only impact and requires user interaction, though public exploit material and a high EPSS score raise concern.

What it is

Adobe Acrobat Reader Plugin before 8.0.0 for Firefox, Internet Explorer and Opera lets remote attackers force the browser to make unauthorized requests to other web sites by placing a URL in the FDF, xml, or xfdf AJAX request parameters after the # character. This is a cross-site request forgery and session-riding flaw, so a page the victim visits can silently drive the browser to act against other sites using the victim's credentials.

Impact

An attacker can make the victim's browser issue unauthorized requests to arbitrary sites, riding the victim's authenticated session to perform state-changing actions. The CVSS 2.0 vector rates integrity impact only (I:P), with no confidentiality or availability impact.

Attack surface

Reached over the network through a crafted web page or PDF that supplies a URL in the FDF, xml, or xfdf AJAX parameters after the # character; the browser plugin processes it. No authentication is required (Au:N), but the victim must visit the malicious content, so user interaction is needed.

Exploitation

Not listed in CISA KEV and no ransomware use is documented. EPSS is high (0.55909, 98.997th percentile), and one reference is tagged Exploit and Patch, indicating public exploit material exists.

What to do

  • Upgrade Adobe Acrobat Reader Plugin to 8.0.0 or later, or apply the vendor patch referenced in the advisory.
  • Apply the distribution updates from Red Hat, SUSE and Gentoo advisories where the plugin is packaged.
  • Disable or remove the browser PDF plugin and open PDFs in a standalone reader to cut the browser attack path.
  • Restrict the plugin from loading untrusted PDF or FDF content and block untrusted sites from triggering plugin requests.
  • Treat cross-site requests from PDF plugin sessions as untrusted and require re-authentication for sensitive actions.

Detection

  • Monitor browser and proxy logs for requests to unexpected external sites originating from PDF plugin activity.
  • Look for FDF, xml, or xfdf parameter values containing a URL after a # character in web or plugin request logs.
  • Alert on cross-site requests that carry session cookies but lack a normal user navigation referer.
  • Review endpoint logs for Acrobat Reader Plugin versions below 8.0.0 on hosts with Firefox, Internet Explorer or Opera.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf
http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html
http://secunia.com/advisories/23812
http://secunia.com/advisories/23882 Vendor Advisory
http://secunia.com/advisories/29065 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200701-16.xml
http://securityreason.com/securityalert/2090 Vendor Advisory
http://securitytracker.com/id?1017469
http://www.redhat.com/support/errata/RHSA-2008-0144.html
http://www.securityfocus.com/archive/1/455801/100/0/threaded
http://www.securityfocus.com/bid/21858
http://www.vupen.com/english/advisories/2007/0032
http://www.wisec.it/vulns.php?page=9 ExploitPatch
https://exchange.xforce.ibmcloud.com/vulnerabilities/31266
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10042
http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf
http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html
http://secunia.com/advisories/23812
http://secunia.com/advisories/23882 Vendor Advisory
http://secunia.com/advisories/29065 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200701-16.xml
http://securityreason.com/securityalert/2090 Vendor Advisory
http://securitytracker.com/id?1017469
http://www.redhat.com/support/errata/RHSA-2008-0144.html
http://www.securityfocus.com/archive/1/455801/100/0/threaded
http://www.securityfocus.com/bid/21858
http://www.vupen.com/english/advisories/2007/0032
http://www.wisec.it/vulns.php?page=9 ExploitPatch
https://exchange.xforce.ibmcloud.com/vulnerabilities/31266
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10042

Track CVE-2007-0044 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-0546Adobe Reader and Acrobat sandbox bypass allows privileged code executionAdobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows contain a sandbox protection bypass. An attacker can escape the Reade…KEVEPSS 22%analysed9.8CVE-2013-3346Adobe Reader and Acrobat memory corruption allows code executionAdobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 contain an out-of-bounds write (CWE-787) that corrupts memory.…KEVEPSS 79%analysed9.8CVE-2013-2729Adobe Reader and Acrobat integer overflow allows code executionAdobe Reader and Acrobat contain an integer overflow (CWE-190) that can be triggered by unspecified vectors, leading to arbitrary code execution. It …KEVEPSS 67%analysed9.8CVE-2011-2462Adobe Reader and Acrobat U3D memory corruption code executionAn out-of-bounds write in the U3D component of Adobe Reader and Acrobat allows remote attackers to corrupt memory and execute arbitrary code. The fla…KEVEPSS 89%analysed8.8CVE-2021-28550Adobe Acrobat and Reader use-after-free allows code executionAdobe Acrobat Reader DC (2021.001.20150, 2020.001.30020, 2017.011.30194 and earlier) and related Acrobat products contain a use-after-free (CWE-416) …KEVEPSS 52%analysed8.8CVE-2021-21017Adobe Acrobat and Reader heap buffer overflow via malicious fileAdobe Acrobat Reader DC (2020.013.20074, 2020.001.30018, 2017.011.30188 and earlier) contains a heap-based buffer overflow (CWE-122/CWE-787) triggere…KEVEPSS 86%analysed8.8CVE-2014-0496Adobe Reader and Acrobat use-after-free code executionAdobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X contain a use-after-free (CWE-416) that allows arbitrary …KEVEPSS 40%analysed8.8CVE-2011-0611Adobe Flash Player type confusion allows remote code executionAdobe Flash Player, Adobe AIR and the Authplay component in Adobe Reader/Acrobat contain a type confusion flaw (CWE-843) reachable through crafted Fl…KEVEPSS 99%analysed

Source: NIST National Vulnerability Database (record CVE-2007-0044), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.