This application requires Javascript for optimal performance.

Adobe.Acrobat.Plugin.XSS

Release Date

Jan 04, 2007

Severity

high

Impact

Execution of arbitrary scripts in the context of hosting site.

Description

It indicates a possible exploit of a cross-site scripting Vulnerability in Adobe Acrobat Plugin that may allow an attacker to execute a malicious script in the victim's browser, within the security context of the hosting site, once the link is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

Affected Products

Adobe Acrobat Reader before 8.0

Recommended Actions

Update to Adobe Acrobat Reader 8.0.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2007-0045

Reference/s

http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf
http://www.disenchant.ch/blog/hacking-with-browser-plugins/34

Reference: VID-13741