First published: Thu Feb 26 2009(Updated: )
Cross-site scripting (XSS) vulnerability in Adobe RoboHelp Server 6 and 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, which is not properly handled when displaying the Help Errors log.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe RoboHelp | =6 | |
Adobe RoboHelp | =7 | |
Adobe RoboHelp | =6 | |
Adobe RoboHelp | =7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0523 is considered a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
To fix CVE-2009-0523, upgrade to the latest patched version of Adobe RoboHelp Server or RoboHelp.
CVE-2009-0523 affects Adobe RoboHelp Server versions 6 and 7, as well as Adobe RoboHelp versions 6 and 7.
CVE-2009-0523 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts into affected applications.
Yes, CVE-2009-0523 can be exploited remotely by attackers through crafted URLs that target the Help Errors log.