First published: Mon May 16 2011(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in RoboHelp 7 and 8, and RoboHelp Server 7 and 8, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to (1) wf_status.htm and (2) wf_topicfs.htm in RoboHTML/WildFireExt/TemplateStock/.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe RoboHelp | =7 | |
Adobe RoboHelp | =8 | |
Adobe RoboHelp | =7 | |
Adobe RoboHelp | =8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0613 is categorized as a medium-severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
To mitigate CVE-2011-0613, update to the latest patched version of Adobe RoboHelp or apply any available security updates from Adobe.
CVE-2011-0613 affects Adobe RoboHelp 7 and 8, as well as Adobe RoboHelp Server 7 and 8.
CVE-2011-0613 may allow attackers to execute arbitrary scripts in the context of a user's browser, potentially leading to data theft or session hijacking.
There are currently no known public exploits specifically targeting CVE-2011-0613, but the nature of the vulnerability could be exploited by an attacker.