Adobe RoboHelp Server Authentication Bypass Vulnerability
BID:36245
Info
Adobe RoboHelp Server Authentication Bypass Vulnerability
| Bugtraq ID: | 36245 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-3068 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 03 2009 12:00AM |
| Updated: | Sep 24 2009 04:10PM |
| Credit: | Intevydis and Stephen Fewer of Harmony Security |
| Vulnerable: |
Adobe RoboHelp Server 8 |
| Not Vulnerable: | |
Discussion
Adobe RoboHelp Server Authentication Bypass Vulnerability
Adobe RoboHelp Server is prone to an authentication-bypass vulnerability. An attacker can exploit this issue to upload and execute arbitrary code with SYSTEM-level privileges.
RoboHelp Server 8.0 is affected; other versions may also be vulnerable.
Adobe RoboHelp Server is prone to an authentication-bypass vulnerability. An attacker can exploit this issue to upload and execute arbitrary code with SYSTEM-level privileges.
RoboHelp Server 8.0 is affected; other versions may also be vulnerable.
Exploit / POC
Adobe RoboHelp Server Authentication Bypass Vulnerability
A working commercial exploit is available through Intevydis. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following example is available:
A working commercial exploit is available through Intevydis. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following example is available:
Solution / Fix
Adobe RoboHelp Server Authentication Bypass Vulnerability
Solution:
Vendor updates are available. Please see the references for details.
Solution:
Vendor updates are available. Please see the references for details.
References
Adobe RoboHelp Server Authentication Bypass Vulnerability
References:
References:
- Adobe RoboHelp Server 8 vulnerability (Intevydis)
- Potential RoboHelp Server 8 Issue (Adobe)
- RoboHelp Server Homepage (Adobe)
- Update on RoboHelp Server 8 Issue (Adobe)
- VulnDisco Pack Professional (Intevydis)
- ZDI-09-066: Adobe RoboHelp Server Arbitrary File Upload and Execute Vulnerabilit (ZDI Disclosures
) - Adobe RoboHelp Server Arbitrary File Upload and Execute Vulnerability (ZDI)
- APSA09-05 Security advisory for RoboHelp Server 8 (Adobe)
- APSB09-14 Security update available for RoboHelp Server 8 (Adobe)