CVE-2008-2640
Multiple cross-site scripting (XSS) vulnerabilities in the Flex 3 History Management feature in Adobe Flex 3.0.1 SDK and Flex Builder 3, and generated applications, allow remote attackers to inject arbitrary web script or HTML via the anchor identifier…
Does this matter?
Lower severity and a low EPSS score (2.77%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the Flex 3 History Management feature in Adobe Flex 3.0.1 SDK and Flex Builder 3, and generated applications, allow remote attackers to inject arbitrary web script or HTML via the anchor identifier to (1) client-side-detection-with-history/history/historyFrame.html, (2) express-installation-with-history/history/historyFrame.html, or (3) no-player-detection-with-history/history/historyFrame.html in templates/html-templates/. NOTE: Firefox 2.0 and possibly other browsers prevent exploitation.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 2.77% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- adobe/flex · adobe/flex builder
- Source
- cve@mitre.org
References
- http://blog.watchfire.com/wfblog/2008/06/javascript-code.htmlExploit
- http://secunia.com/advisories/30746Patch, Vendor Advisory
- http://securitytracker.com/id?1020301
- http://www.adobe.com/support/security/bulletins/apsb08-14.htmlPatch
- http://www.securityfocus.com/bid/29778Patch
- http://www.vupen.com/english/advisories/2008/1862
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43150
- http://blog.watchfire.com/wfblog/2008/06/javascript-code.htmlExploit
- http://secunia.com/advisories/30746Patch, Vendor Advisory
- http://securitytracker.com/id?1020301
- http://www.adobe.com/support/security/bulletins/apsb08-14.htmlPatch
- http://www.securityfocus.com/bid/29778Patch
- http://www.vupen.com/english/advisories/2008/1862
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43150
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.