Lucene search

K
cveAdobeCVE-2012-0765
HistoryFeb 15, 2012 - 1:55 a.m.

CVE-2012-0765

2012-02-1501:55:02
CWE-79
adobe
web.nvd.nist.gov
32
adobe
robohelp
xss
vulnerabilities
remote attackers
web script
html
crafted url

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.002

Percentile

60.4%

Multiple cross-site scripting (XSS) vulnerabilities in Adobe RoboHelp 8 and 9 for Word allow remote attackers to inject arbitrary web script or HTML via a crafted URL, related to certain .htm files in (1) template_stock and (2) template_csh directories.

Affected configurations

Nvd
Node
adoberobohelpMatch8
OR
adoberobohelpMatch8.0.1
OR
adoberobohelpMatch8.0.2
OR
adoberobohelpMatch9
OR
adoberobohelpMatch9.0.0.228
OR
adoberobohelpMatch9.0.1
OR
adoberobohelpMatch9.0.1.232
OR
adoberobohelpMatch9.0.2
AND
microsoftword
OR
microsoftwindows
VendorProductVersionCPE
adoberobohelp8cpe:2.3:a:adobe:robohelp:8:*:*:*:*:*:*:*
adoberobohelp8.0.1cpe:2.3:a:adobe:robohelp:8.0.1:*:*:*:*:*:*:*
adoberobohelp8.0.2cpe:2.3:a:adobe:robohelp:8.0.2:*:*:*:*:*:*:*
adoberobohelp9cpe:2.3:a:adobe:robohelp:9:*:*:*:*:*:*:*
adoberobohelp9.0.0.228cpe:2.3:a:adobe:robohelp:9.0.0.228:*:*:*:*:*:*:*
adoberobohelp9.0.1cpe:2.3:a:adobe:robohelp:9.0.1:*:*:*:*:*:*:*
adoberobohelp9.0.1.232cpe:2.3:a:adobe:robohelp:9.0.1.232:*:*:*:*:*:*:*
adoberobohelp9.0.2cpe:2.3:a:adobe:robohelp:9.0.2:*:*:*:*:*:*:*
microsoftword*cpe:2.3:a:microsoft:word:*:*:*:*:*:*:*:*
microsoftwindows*cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.002

Percentile

60.4%

Related for CVE-2012-0765