First published: Fri Aug 21 2009(Updated: )
Cross-site scripting (XSS) vulnerability in index.template.html in the express-install templates in the SDK in Adobe Flex before 3.4, when the installed Flash version is older than a specified requiredMajorVersion value, allows remote attackers to inject arbitrary web script or HTML via the query string.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Flex SDK | <3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1879 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2009-1879, upgrade to Adobe Flex SDK version 3.4 or later.
CVE-2009-1879 affects Adobe Flex SDK versions prior to 3.4.
CVE-2009-1879 is a cross-site scripting (XSS) vulnerability.
Yes, CVE-2009-1879 can allow remote attackers to inject and execute arbitrary web script or HTML.