Vulnerability Name: | CVE-2005-1306 (CCN-21006) | ||||||||
Assigned: | 2005-06-15 | ||||||||
Published: | 2005-06-15 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the "XML External Entity vulnerability." | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2005-1306 Source: CCN Type: Adobe Download Web page downloads Source: CCN Type: Adobe Support Knowledgebase Document 331710 XML External Entity vulnerability (Adobe Reader and Acrobat 7.0-7.0.1) Source: CONFIRM Type: Patch, Vendor Advisory http://www.adobe.com/support/techdocs/331710.html Source: CCN Type: OSVDB ID: 17325 Adobe Reader/Acrobat XML Script Local File Enumeration Source: BID Type: Exploit, Patch, Vendor Advisory 13962 Source: CCN Type: BID-13962 Adobe Acrobat/Adobe Reader File Existence and Disclosure Vulnerability Source: XF Type: UNKNOWN adobe-xml-file-disclosure(21006) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |