Adobe RoboHelp CVE-2017-3104 Cross Site Scripting Vulnerability
BID:100707
Info
Adobe RoboHelp CVE-2017-3104 Cross Site Scripting Vulnerability
| Bugtraq ID: | 100707 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-3104 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2017 12:00AM |
| Updated: | Sep 12 2017 12:00AM |
| Credit: | Reynold Regan of CNSI - Center for Technology & Innovation |
| Vulnerable: |
Adobe RoboHelp 9 9.0.1.262 Adobe RoboHelp 9 9.0.1.232 Adobe RoboHelp 2017.0.1 Adobe RoboHelp 2015.0.4 Adobe RoboHelp 2015.0.3 Adobe RoboHelp 8.0.1 Adobe RoboHelp 9.0.2 Adobe RoboHelp 9.0.1.232 Adobe RoboHelp 9.0.1 Adobe RoboHelp 9.0.0.228 Adobe RoboHelp 9 Adobe RoboHelp 8.0.2 Adobe RoboHelp 8 Adobe RoboHelp 7.0.3 Adobe RoboHelp 7.0.2 Adobe RoboHelp 7.0.1 Adobe RoboHelp 7 Adobe RoboHelp 6 Adobe RoboHelp 12.0.4.460 Adobe RoboHelp 11 Adobe RoboHelp 10 |
| Not Vulnerable: |
Adobe RoboHelp 2017.0.2 Adobe RoboHelp 12.0.4.460 (Hotfix) |
Discussion
Adobe RoboHelp CVE-2017-3104 Cross Site Scripting Vulnerability
Adobe RoboHelp is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker could exploit this vulnerability to execute arbitrary script code in the context of the affected website. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
The following versions are vulnerable:
Adobe RoboHelp version 2017.0.1 and prior.
Adobe RoboHelp version 12.0.4.460 and prior.
Adobe RoboHelp is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker could exploit this vulnerability to execute arbitrary script code in the context of the affected website. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
The following versions are vulnerable:
Adobe RoboHelp version 2017.0.1 and prior.
Adobe RoboHelp version 12.0.4.460 and prior.
Exploit / POC
Adobe RoboHelp CVE-2017-3104 Cross Site Scripting Vulnerability
To exploit this issue an attacker must entice a victim into following a malicious URI.
To exploit this issue an attacker must entice a victim into following a malicious URI.
Solution / Fix
Adobe RoboHelp CVE-2017-3104 Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Adobe RoboHelp CVE-2017-3104 Cross Site Scripting Vulnerability
References:
References: