PT-2012-2853 · Adobe · Robohelp

Published

2012-02-15

·

Updated

2017-08-29

·

CVE-2012-0765

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Adobe RoboHelp versions 8 and 9
Description The issue concerns multiple cross-site scripting (XSS) vulnerabilities that allow remote attackers to inject arbitrary web script or HTML via a crafted URL. This is related to certain .htm files in the template stock and template csh directories.
Recommendations For Adobe RoboHelp version 8, update to a version that includes the fix for this issue. For Adobe RoboHelp version 9, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the template stock and template csh directories to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-0765

Affected Products

Robohelp