CVE-2008-2640
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in the Flex 3 History Management feature in Adobe Flex 3.0.1 SDK and Flex Builder 3, and generated applications, allow remote attackers to inject arbitrary web script or HTML via the anchor identifier to (1) client-side-detection-with-history/history/historyFrame.html, (2) express-installation-with-history/history/historyFrame.html, or (3) no-player-detection-with-history/history/historyFrame.html in templates/html-templates/. NOTE: Firefox 2.0 and possibly other browsers prevent exploitation.
Múltiples vulnerabilidades de ejecución de comandos en sitios cruzados (XSS) en Flex 3 History Management en Adobe Flex 3.0.1 SDK, Flex Builder 3 y las aplicaciones generadas con éstos, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del marcador identificador al (1) client-side-detection-with-history/history/historyFrame.html, (2) express-installation-with-history/history/historyFrame.html, o (3) no-player-detection-with-history/history/historyFrame.html en templates/html-templates/. NOTA: Firefox 2.0 y probablemente otros navegadores evitan la explotación.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-06-09 CVE Reserved
- 2008-06-18 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- 2024-10-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://securitytracker.com/id?1020301 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/1862 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/43150 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://blog.watchfire.com/wfblog/2008/06/javascript-code.html | 2024-08-07 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/30746 | 2017-08-08 | |
http://www.adobe.com/support/security/bulletins/apsb08-14.html | 2017-08-08 | |
http://www.securityfocus.com/bid/29778 | 2017-08-08 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Adobe Search vendor "Adobe" | Flex Search vendor "Adobe" for product "Flex" | 3.0.1 Search vendor "Adobe" for product "Flex" and version "3.0.1" | sdk |
Affected
| ||||||
Adobe Search vendor "Adobe" | Flex Builder Search vendor "Adobe" for product "Flex Builder" | 3 Search vendor "Adobe" for product "Flex Builder" and version "3" | - |
Affected
|