Multiple cross-site scripting (XSS) vulnerabilities in Adobe RoboHelp 8 and 9 for Word allow remote attackers to inject arbitrary web script or HTML via a crafted URL, related to certain .htm files in (1) template_stock and (2) template_csh directories.
2012-02-15T01:55:02.400
2025-04-11T00:51:21.963
Deferred
CVSSv2: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | adobe | robohelp | 8 | Yes |
Application | adobe | robohelp | 8.0.1 | Yes |
Application | adobe | robohelp | 8.0.2 | Yes |
Application | adobe | robohelp | 9 | Yes |
Application | adobe | robohelp | 9.0.0.228 | Yes |
Application | adobe | robohelp | 9.0.1 | Yes |
Application | adobe | robohelp | 9.0.1.232 | Yes |
Application | adobe | robohelp | 9.0.2 | Yes |
Application | microsoft | word | * | No |
Operating System | microsoft | windows | * | No |