CVE-2008-2991: XSS
Published Jul 9, 2008
·Updated
Cross-site scripting (XSS) vulnerability in Adobe RoboHelp Server 6 and 7 allows remote attackers to inject arbitrary web script or HTML via vectors related to the Help Errors log.
Affected Software
2 affected components
Adobe RoboHelp Server=6
Adobe RoboHelp Server=7
Event History
Jul 9, 2008
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2991?
CVE-2008-2991 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2008-2991?
To fix CVE-2008-2991, upgrade to a patched version of Adobe RoboHelp Server that addresses the XSS vulnerability.
3
What versions of Adobe RoboHelp Server are affected by CVE-2008-2991?
CVE-2008-2991 affects Adobe RoboHelp Server versions 6 and 7.
4
What type of attack is possible with CVE-2008-2991?
CVE-2008-2991 allows remote attackers to inject arbitrary web scripts or HTML into the application.
5
Can CVE-2008-2991 be exploited without authentication?
Yes, CVE-2008-2991 can potentially be exploited by an attacker without the need for authentication.