{"api_version":"1","generated_at":"2026-07-23T11:07:54+00:00","cve":"CVE-2008-6062","urls":{"html":"https://cve.report/CVE-2008-6062","api":"https://cve.report/api/cve/CVE-2008-6062.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-6062","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-6062"},"summary":{"title":"CVE-2008-6062","description":"Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) files created by Adobe Dreamweaver, when the Insert Flash Video feature is used, allows remote attackers to inject arbitrary web script or HTML via an asfunction: URI in the skinName parameter.  NOTE: this may overlap CVE-2007-6242, CVE-2007-6244, or CVE-2007-6637.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-02-05 01:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/485722/100/100/threaded","name":"http://www.securityfocus.com/archive/1/485722/100/100/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/249337","name":"http://www.kb.cert.org/vuls/id/249337","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Vulnerability Note VU#249337","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://docs.google.com/View?docid=ajfxntc4dmsq_14dt57ssdw","name":"http://docs.google.com/View?docid=ajfxntc4dmsq_14dt57ssdw","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"XSS Vulnerabilities in Common...","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.adobe.com/support/security/bulletins/apsb07-20.html","name":"http://www.adobe.com/support/security/bulletins/apsb07-20.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Adobe - Security Advisories : APSB07-20: Flash Player update available to address security vulnerabilities","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-6062","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-6062","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"6062","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"dreamweaver","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T11:20:24.320Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://docs.google.com/View?docid=ajfxntc4dmsq_14dt57ssdw"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.adobe.com/support/security/bulletins/apsb07-20.html"},{"name":"VU#249337","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/249337"},{"name":"20080102 XSS Vulnerabilities in Common Shockwave Flash Files","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/485722/100/100/threaded"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-01-08T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) files created by Adobe Dreamweaver, when the Insert Flash Video feature is used, allows remote attackers to inject arbitrary web script or HTML via an asfunction: URI in the skinName parameter.  NOTE: this may overlap CVE-2007-6242, CVE-2007-6244, or CVE-2007-6637."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-11T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://docs.google.com/View?docid=ajfxntc4dmsq_14dt57ssdw"},{"tags":["x_refsource_MISC"],"url":"http://www.adobe.com/support/security/bulletins/apsb07-20.html"},{"name":"VU#249337","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/249337"},{"name":"20080102 XSS Vulnerabilities in Common Shockwave Flash Files","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/485722/100/100/threaded"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-6062","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) files created by Adobe Dreamweaver, when the Insert Flash Video feature is used, allows remote attackers to inject arbitrary web script or HTML via an asfunction: URI in the skinName parameter.  NOTE: this may overlap CVE-2007-6242, CVE-2007-6244, or CVE-2007-6637."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://docs.google.com/View?docid=ajfxntc4dmsq_14dt57ssdw","refsource":"MISC","url":"http://docs.google.com/View?docid=ajfxntc4dmsq_14dt57ssdw"},{"name":"http://www.adobe.com/support/security/bulletins/apsb07-20.html","refsource":"MISC","url":"http://www.adobe.com/support/security/bulletins/apsb07-20.html"},{"name":"VU#249337","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/249337"},{"name":"20080102 XSS Vulnerabilities in Common Shockwave Flash Files","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/485722/100/100/threaded"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-6062","datePublished":"2009-02-05T01:00:00.000Z","dateReserved":"2009-02-04T00:00:00.000Z","dateUpdated":"2024-08-07T11:20:24.320Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-02-05 01:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:dreamweaver:*:*:*:*:*:*:*:*","matchCriteriaId":"4612B738-830D-417F-BD8B-7AA15010F193"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"6062","Ordinal":"1","Title":"CVE-2008-6062","CVE":"CVE-2008-6062","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"6062","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) files created by Adobe Dreamweaver, when the Insert Flash Video feature is used, allows remote attackers to inject arbitrary web script or HTML via an asfunction: URI in the skinName parameter.  NOTE: this may overlap CVE-2007-6242, CVE-2007-6244, or CVE-2007-6637.","Type":"Description","Title":"CVE-2008-6062"},{"CveYear":"2008","CveId":"6062","Ordinal":"2","NoteData":"2009-02-04","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"6062","Ordinal":"3","NoteData":"2018-10-11","Type":"Other","Title":"Modified"}]}}}