2.6
CVSSv2

CVE-2009-1879

Published: 21/08/2009 Updated: 20/03/2020
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 265
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in index.template.html in the express-install templates in the SDK in Adobe Flex prior to 3.4, when the installed Flash version is older than a specified requiredMajorVersion value, allows remote malicious users to inject arbitrary web script or HTML via the query string.

Vulnerable Product Search on Vulmon Subscribe to Product

adobe flex sdk

Exploits

source: wwwsecurityfocuscom/bid/36087/info Adobe Flex SDK is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input to express-install template files An attacker could exploit this vulnerability to execute arbitrary script code in the context of a web application built using the SDK This ...