=====================================================================
                                    CERT-Renater

                         Note d'Information No. 2008/VULN284
_____________________________________________________________________

DATE                      : 09/07/2008

HARDWARE PLATFORM(S)      : /

OPERATING SYSTEM(S)       : Systems running RoboHelp Server.

======================================================================
http://www.adobe.com/support/security/bulletins/apsb08-16.html
______________________________________________________________________

Patch available for RoboHelp Server Cross-Site Scripting issue

Release date: July 8, 2008

Vulnerability identifier: APSB08-16

CVE number: CVE-2008-2991

Platform: Windows

Affected software versions:

     * RoboHelp Server 6
     * RoboHelp Server 7

Summary

A specially crafted URL could be used to create a cross-site scripting
attack on RoboHelp Server 6 and RoboHelp Server 7 installations.

Solution

Adobe strongly recommends users update their RoboHelp Server 6 and
Robohelp Server 7 installations using the instructions below.

    1. Download the update file.
    2. Replace files Report_API.asp, Report_Template.asp and SQL_Lib.asp
       with       their respective updated files at following location:
       <RoboHelpServer Installation Directory>\Reports
       (e.g. D:\Program Files\Adobe\RoboHelp Server 7\Reports)
    3. Restart RoboHelp Server.

Severity rating

Adobe categorizes this as an important issue and recommends affected
users patch their installations.

Details

A specially crafted URL could be used to create a cross-site scripting
attack against RoboHelp Server 6 and RoboHelp Server 7. An attacker
would need to have access to the RoboHelp Help Errors log, or convince
someone with access to the RoboHelp Help Errors log to click on a
malicious URL, in order to execute the attack. RoboHelp 6 and RoboHelp 7
(non-Server releases) are not vulnerable to this issue.


Acknowledgments

Adobe would like to thank the Vulnerability Research Team of Assurent
Secure Technologies, a TELUS company, and Greg Patton of PropertyInfo 
Corporation for reporting this vulnerability and for working with us to
help protect our customers' security.

Adobe Disclaimer
License agreement

By using software of Adobe Systems Incorporated or its subsidiaries
("Adobe");you agree to the following terms and conditions. If you do not 
agree with such terms and conditions; do not use the software. The terms 
of an end user license agreement accompanying a particular software file 
upon installation or download of the software shall supersede the terms
presented below.

The export and re-export of Adobe software products are controlled by
the United States Export Administration Regulations and such software
may not be exported or re-exported to Cuba; Iran; Iraq; Libya; North
Korea; Sudan; or Syria or any country to which the United States
embargoes goods. In addition; Adobe software may not be distributed to
persons on the Table of Denial Orders; the Entity List; or the List of
Specially Designated Nationals.

By downloading or using an Adobe software product you are certifying
that you are not a national of Cuba; Iran; Iraq; Libya; North Korea;
Sudan; or Syria or any country to which the United States embargoes
goods and that you are not a person on the Table of Denial Orders; the
Entity List; or the List of Specially Designated Nationals. If the
software is designed for use with an application software product (the
"Host Application") published by Adobe; Adobe grants you a non-exclusive
license to use such software with the Host Application only; provided
you possess a valid license from Adobe for the Host Application. Except
as set forth below; such software is licensed to you subject to the
terms and conditions of the End User License Agreement from Adobe
governing your use of the Host Application.

DISCLAIMER OF WARRANTIES: YOU AGREE THAT ADOBE HAS MADE NO EXPRESS
WARRANTIES TO YOU REGARDING THE SOFTWARE AND THAT THE SOFTWARE IS BEING
PROVIDED TO YOU "AS IS" WITHOUT WARRANTY OF ANY KIND. ADOBE DISCLAIMS
ALL WARRANTIES WITH REGARD TO THE SOFTWARE; EXPRESS OR IMPLIED;
INCLUDING; WITHOUT LIMITATION; ANY IMPLIED WARRANTIES OF FITNESS FOR A
PARTICULAR PURPOSE; MERCHANTABILITY; MERCHANTABLE QUALITY OR
NONINFRINGEMENT OF THIRD PARTY RIGHTS. Some states or
jurisdictions do not allow the exclusion of implied warranties; so the
above limitations may not apply to you.

LIMIT OF LIABILITY: IN NO EVENT WILL ADOBE BE LIABLE TO YOU FOR ANY LOSS 
OF USE; INTERRUPTION OF BUSINESS; OR ANY DIRECT; INDIRECT; SPECIAL;
INCIDENTAL;OR CONSEQUENTIAL DAMAGES OF ANY KIND (INCLUDING LOST PROFITS)
REGARDLESS OF THE FORM OF ACTION WHETHER IN CONTRACT; TORT (INCLUDING
NEGLIGENCE); STRICT PRODUCT LIABILITY OR OTHERWISE; EVEN IF ADOBE HAS
BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. Some states or
jurisdictions do not allow the exclusion or limitation of incidental or
consequential damages; so the above limitation or exclusion may not
apply to you.

======================================================================

           =========================================================
           Les serveurs de référence du CERT-Renater
           http://www.urec.fr/securite
           http://www.cru.fr/securite
           http://www.renater.fr
           =========================================================
           + CERT-RENATER          | tel : 01-53-94-20-44          +
           + 151 bd de l'Hopital   | fax : 01-53-94-20-41          +
           + 75013 Paris           | email: certsvp@renater.fr     +
           =========================================================




