CVE-2012-0765: XSS
Published Feb 15, 2012
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in Adobe RoboHelp 8 and 9 for Word allow remote attackers to inject arbitrary web script or HTML via a crafted URL, related to certain .htm files in (1) templatestock and (2) templatecsh directories.
Affected Software
10 affected components
Adobe RoboHelp=8
Adobe RoboHelp=8.0.1
Adobe RoboHelp=8.0.2
Adobe RoboHelp=9
Adobe RoboHelp=9.0.0.228
Adobe RoboHelp=9.0.1
Adobe RoboHelp=9.0.1.232
Adobe RoboHelp=9.0.2
Microsoft word
Microsoft Windows
Event History
Feb 15, 2012
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0765?
CVE-2012-0765 has a medium severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2012-0765?
To fix CVE-2012-0765, update Adobe RoboHelp to the latest version recommended by Adobe.
3
What versions of Adobe RoboHelp are affected by CVE-2012-0765?
CVE-2012-0765 affects Adobe RoboHelp versions 8.0, 8.0.1, 8.0.2, and all versions of 9.
4
What type of vulnerability is CVE-2012-0765?
CVE-2012-0765 is classified as a cross-site scripting (XSS) vulnerability.
5
Can CVE-2012-0765 be exploited remotely?
Yes, CVE-2012-0765 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.