Vulnerability Description
The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the "XML External Entity vulnerability."
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Acrobat | 7.0 |
| Adobe | Acrobat Reader | 7.0 |
Related Weaknesses (CWE)
References
- http://www.adobe.com/support/techdocs/331710.htmlBroken LinkPatchVendor Advisory
- http://www.securityfocus.com/bid/13962Broken LinkExploitPatch
- http://www.adobe.com/support/techdocs/331710.htmlBroken LinkPatchVendor Advisory
- http://www.securityfocus.com/bid/13962Broken LinkExploitPatch
FAQ
What is CVE-2005-1306?
CVE-2005-1306 is a vulnerability with a CVSS score of 7.5 (HIGH). The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the "XML External Entity vulner...
How severe is CVE-2005-1306?
CVE-2005-1306 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-1306?
Check the references section above for vendor advisories and patch information. Affected products include: Adobe Acrobat, Adobe Acrobat Reader.