Adobe RoboHelp CVE-2017-3105 Open Redirect Vulnerability
BID:100709
Info
Adobe RoboHelp CVE-2017-3105 Open Redirect Vulnerability
| Bugtraq ID: | 100709 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-3105 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2017 12:00AM |
| Updated: | Sep 12 2017 12:00AM |
| Credit: | Reynold Regan of CNSI - Center for Technology & Innovation |
| Vulnerable: |
Adobe RoboHelp 9 9.0.1.262 Adobe RoboHelp 9 9.0.1.232 Adobe RoboHelp 2017.0.1 Adobe RoboHelp 2015.0.4 Adobe RoboHelp 2015.0.3 Adobe RoboHelp 8.0.1 Adobe RoboHelp 9.0.2 Adobe RoboHelp 9.0.1.232 Adobe RoboHelp 9.0.1 Adobe RoboHelp 9.0.0.228 Adobe RoboHelp 9 Adobe RoboHelp 8.0.2 Adobe RoboHelp 8 Adobe RoboHelp 7.0.2 Adobe RoboHelp 7.0.1 Adobe RoboHelp 7 Adobe RoboHelp 6 Adobe RoboHelp 12.0.4.460 Adobe RoboHelp 11 Adobe RoboHelp 10 |
| Not Vulnerable: |
Adobe RoboHelp 2017.0.2 Adobe RoboHelp 12.0.4.460 (Hotfix) |
Discussion
Adobe RoboHelp CVE-2017-3105 Open Redirect Vulnerability
Adobe RoboHelp is prone to an open-redirect vulnerability.
An attacker can leverage this issue by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
The following versions are vulnerable:
Adobe RoboHelp version 2017.0.1 and prior.
Adobe RoboHelp version 12.0.4.460 and prior.
Adobe RoboHelp is prone to an open-redirect vulnerability.
An attacker can leverage this issue by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
The following versions are vulnerable:
Adobe RoboHelp version 2017.0.1 and prior.
Adobe RoboHelp version 12.0.4.460 and prior.
Exploit / POC
Adobe RoboHelp CVE-2017-3105 Open Redirect Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Adobe RoboHelp CVE-2017-3105 Open Redirect Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Adobe RoboHelp CVE-2017-3105 Open Redirect Vulnerability
References:
References: