Unrestricted File Upload Vulnerability in Adobe RoboHelp Server
CVE-2009-3068

Currently unrated

Key Information:

Vendor
Adobe
Vendor
CVE Published:
4 September 2009

Summary

The vulnerability allows remote attackers to execute arbitrary code through an unrestricted file upload mechanism in Adobe RoboHelp Server 8. By uploading a malicious Java Archive (.jsp) file during a PUBLISH operation and directly accessing it via a URL, attackers can compromise the server, leading to potential data breaches and unauthorized system access.

References

EPSS Score

90% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.