Cross-Site Scripting Vulnerability in Adobe RoboHelp Versions 8 and 9
CVE-2012-0765

Currently unrated

Key Information:

Vendor

Adobe

Status
Vendor
CVE Published:
15 February 2012

What is CVE-2012-0765?

Multiple cross-site scripting vulnerabilities exist in Adobe RoboHelp 8 and 9 that enable remote attackers to inject arbitrary web scripts or HTML into documents via specially crafted URLs. This issue is particularly relevant for certain .htm files located in the template_stock and template_csh directories, which can be exploited to execute malicious scripts in the context of a user's session, posing serious security risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.