CVE-2009-3068: Critical severity adobe robohelp vulnerability
Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows remote attackers to execute arbitrary code by uploading a Java Archive (.jsp) file during a PUBLISH action, then accessing it via a direct request to the file in the robohelp/robo/reserved/web directory under its sessionid subdirectory, as demonstrated by the vdadobe module in VulnDisco Pack Professional 8.7 through 8.11.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3068?
CVE-2009-3068 has a high severity rating due to the potential for remote code execution.
How do I fix CVE-2009-3068?
To fix CVE-2009-3068, update Adobe RoboHelp Server to the latest version that addresses this vulnerability.
What type of attack is enabled by CVE-2009-3068?
CVE-2009-3068 enables remote attackers to execute arbitrary code through unrestricted file uploads.
Which software is affected by CVE-2009-3068?
CVE-2009-3068 specifically affects Adobe RoboHelp Server version 8.
Can CVE-2009-3068 be exploited without authentication?
Yes, CVE-2009-3068 can be exploited without authentication during a PUBLISH action.