Cross-site scripting (XSS) vulnerability in Adobe RoboHelp 8 and 9 before 9.0.1.262, and RoboHelp Server 8 and 9, allows remote attackers to inject arbitrary web script or HTML via the URI, related to template_stock/whutils.js.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://www.us-cert.gov/cas/techalerts/TA11-222A.html | third party advisory us government resource |
http://www.adobe.com/support/security/bulletins/apsb11-23.html | patch vendor advisory |
http://securityreason.com/securityalert/8334 | third party advisory |