CVE-2008-2640
Adobe Flex - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in the Flex 3 History Management feature in Adobe Flex 3.0.1 SDK and Flex Builder 3, and generated applications, allow remote attackers to inject arbitrary web script or HTML via the anchor identifier to (1) client-side-detection-with-history/history/historyFrame.html, (2) express-installation-with-history/history/historyFrame.html, or (3) no-player-detection-with-history/history/historyFrame.html in templates/html-templates/. NOTE: Firefox 2.0 and possibly other browsers prevent exploitation.
References (7)
Scores
EPSS
0.0280
EPSS Percentile
85.9%
Classification
CWE
CWE-79
Status
draft
Affected Products (2)
adobe/flex
adobe/flex_builder
Timeline
Published
Jun 18, 2008
Tracked Since
Feb 18, 2026