Executive Summary

Informations
Name CVE-2011-2133 First vendor Publication 2011-08-11
Vendor Cve Last vendor Modification 2011-10-04

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:N/I:P/A:N)
Cvss Base Score 4.3 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Cross-site scripting (XSS) vulnerability in Adobe RoboHelp 8 and 9 before 9.0.1.262, and RoboHelp Server 8 and 9, allows remote attackers to inject arbitrary web script or HTML via the URI, related to template_stock/whutils.js.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2133

CWE : Common Weakness Enumeration

idName
CWE-79Failure to Preserve Web Page Structure ('Cross-site Scripting')

CPE : Common Platform Enumeration

TypeDescriptionCount
Application3
Application2

Open Source Vulnerability Database (OSVDB)

idDescription
74430Adobe RoboHelp index.html location.hash DOM Property XSS

Information Assurance Vulnerability Management (IAVM)

DateDescription
2011-08-11IAVM : 2011-B-0095 - Adobe RoboHelp Cross-Site Scripting Vulnerability
Severity : Category II - VMSKEY : V0029770

Nessus® Vulnerability Scanner

DateDescription
2013-05-04Name : An application on the remote Windows host has a cross-site scripting vulnerab...
File : robohelp_apsb11_23.nasl - Type : ACT_GATHER_INFO

Internal Sources (Detail)

SourceUrl
CERT http://www.us-cert.gov/cas/techalerts/TA11-222A.html
CONFIRM http://www.adobe.com/support/security/bulletins/apsb11-23.html
SREASON http://securityreason.com/securityalert/8334

Alert History

If you want to see full details history, please login or register.
0
1
2
DateInformations
2014-02-17 11:02:45
  • Multiple Updates
2013-11-11 12:39:26
  • Multiple Updates
2013-05-10 23:01:11
  • Multiple Updates