XSS in Adobe Reader and Adobe Acrobat

Published: 2006-12-16 | Updated: 2017-03-20
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2007-0045
Exploitation vector Network
Public exploit N/A
Vulnerable software
Adobe Reader
Client/Desktop applications / Office applications

Adobe Acrobat
Client/Desktop applications / Office applications

Vendor Adobe

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Cross-site scripting


Risk: Low


CVE-ID: CVE-2007-0045

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Exploit availability: No


The vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-input passed via FDF, XML, or XFDF parameter. A remote attacker can create a specially .pdf URL, trick the victim to follow it and execute arbitrary HTML and script code in user’s browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Update Adobe Reader and Acrobat 7.x to version 7.1.4
Update Adobe Reader and Acrobat 8.x to version 8.1.7.
Update Adobe Reader and Acrobat 9.x to version 9.2.

Vulnerable software versions

Adobe Reader: 7.0 - 7.1.3, 8.0 - 8.1.6, 9.0 - 9.1.3

Adobe Acrobat: 9.0 - 9.1.3, 8.0 - 8.1.6, 7.0 - 7.1.3

CPE2.3 External links


Q & A

Can this vulnerability be exploited remotely?

How the attacker can exploit this vulnerability?

Is there known malware, which exploits this vulnerability?