CVE-2009-1879: XSS
Published Aug 21, 2009
·Updated
Cross-site scripting (XSS) vulnerability in index.template.html in the express-install templates in the SDK in Adobe Flex before 3.4, when the installed Flash version is older than a specified requiredMajorVersion value, allows remote attackers to inject arbitrary web script or HTML via the query string.
Affected Software
1 affected component
Adobe Flex SDK<3.4
Remediation
Event History
Aug 21, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-1879?
CVE-2009-1879 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2009-1879?
To fix CVE-2009-1879, upgrade to Adobe Flex SDK version 3.4 or later.
3
What systems are affected by CVE-2009-1879?
CVE-2009-1879 affects Adobe Flex SDK versions prior to 3.4.
4
What type of vulnerability is CVE-2009-1879?
CVE-2009-1879 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2009-1879 allow attackers to execute code?
Yes, CVE-2009-1879 can allow remote attackers to inject and execute arbitrary web script or HTML.