VendorsAdoberobohelp_serverall versions
Vulnerabilities

Adobe RoboHelp Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2009-3068
Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows remote attackers to execute arbitrary code by uploading a Java Archive (.jsp) file during a PUBLISH action, then accessing it via a direct request to the file in the robohelp/robo/reserved/web directory under its sessionid subdirectory, as demonstrated by the vd_adobe module in VulnDisco Pack Professional 8.7 through 8.11.
Published 2009-09-04 · Modified
9.32 PoCEPSS 0.782
CVE-2021-42727
Adobe Bridge Buffer Overflow Arbitrary code execution
Published 2021-11-22 · Modified
9.3EPSS 0.394
CVE-2021-28588
Adobe RoboHelp Server folderId Directory Traversal Remote Code Execution Vulnerability
Published 2021-06-28 · Modified
9.0EPSS 0.062
CVE-2022-30670
Escalate Privileges to Server Admin - Robohelp Server
Published 2022-06-16 · Modified
9.0EPSS 0.015
CVE-2023-22274
ZDI-CAN-21305: Adobe RoboHelp Server UpdateCommandStream XML External Entity Processing Information Disclosure Vulnerability
Published 2023-11-17 · Modified
7.5EPSS 0.015
CVE-2023-22272
ZDI-CAN-21309: Adobe RoboHelp Server resolveDistinguishedName LDAP Injection Information Disclosure Vulnerability
Published 2023-11-17 · Modified
7.5EPSS 0.014
CVE-2023-22275
ZDI-CAN-21306: Adobe RoboHelp Server GetNewUserId SQL Injection Information Disclosure Vulnerability
Published 2023-11-17 · Modified
7.5EPSS 0.013
CVE-2023-22273
ZDI-CAN-21307: Adobe RoboHelp Server OnPublishFile Directory Traversal Remote Code Execution Vulnerability
Published 2023-11-17 · Modified
7.2EPSS 0.019
CVE-2023-22268
ZDI-CAN-21308: Adobe RoboHelp Server getRHSGroupsForRoles SQL Injection Information Disclosure Vulnerability
Published 2023-11-17 · Modified
6.5EPSS 0.012
CVE-2008-2991
Cross-site scripting (XSS) vulnerability in Adobe RoboHelp Server 6 and 7 allows remote attackers to inject arbitrary web script or HTML via vectors related to the Help Errors log.
Published 2008-07-09 · Modified
6.1EPSS 0.165
CVE-2007-1280
Cross-site scripting (XSS) vulnerability in Adobe RoboHelp X5, 6, and Server 6 allows remote attackers to inject arbitrary web script or HTML via a URL after a # (hash) in the URL path, as demonstrated using en/frameset-7.html, and possibly other unspecified vectors involving templates and (1) whstart.js and (2) whcsh_home.htm in WebHelp, (3) wf_startpage.js and (4) wf_startqs.htm in FlashHelp, or (5) WindowManager.dll in RoboHelp Server 6.
Published 2007-05-09 · Modified
4.31 PoCEPSS 0.056
CVE-2011-2133
Cross-site scripting (XSS) vulnerability in Adobe RoboHelp 8 and 9 before 9.0.1.262, and RoboHelp Server 8 and 9, allows remote attackers to inject arbitrary web script or HTML via the URI, related to template_stock/whutils.js.
Published 2011-08-11 · Modified
4.3EPSS 0.030
CVE-2009-0524
Cross-site scripting (XSS) vulnerability in Adobe RoboHelp 6 and 7, and RoboHelp Server 6 and 7, allows remote attackers to inject arbitrary web script or HTML via vectors involving files produced by RoboHelp.
Published 2009-02-26 · Modified
4.3EPSS 0.021
CVE-2009-0523
Cross-site scripting (XSS) vulnerability in Adobe RoboHelp Server 6 and 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, which is not properly handled when displaying the Help Errors log.
Published 2009-02-26 · Modified
4.3EPSS 0.021
CVE-2010-2886
Multiple cross-site scripting (XSS) vulnerabilities in Adobe RoboHelp 7 and 8, and RoboHelp Server 7 and 8, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2010-10-26 · Modified
4.3EPSS 0.018
CVE-2011-0613
Multiple cross-site scripting (XSS) vulnerabilities in RoboHelp 7 and 8, and RoboHelp Server 7 and 8, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to (1) wf_status.htm and (2) wf_topicfs.htm in RoboHTML/WildFireExt/TemplateStock/.
Published 2011-05-16 · Modified
4.3EPSS 0.017
CVE-2010-2885
Cross-site scripting (XSS) vulnerability in Adobe RoboHelp 7 and 8, and RoboHelp Server 7 and 8, allows remote attackers to inject arbitrary web script or HTML via vectors related to WebHelp generation with RoboHelp for Word.
Published 2010-10-26 · Modified
4.3EPSS 0.017