CVE-2009-1879
Adobe Flex SDK < 3.4 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in index.template.html in the express-install templates in the SDK in Adobe Flex before 3.4, when the installed Flash version is older than a specified requiredMajorVersion value, allows remote attackers to inject arbitrary web script or HTML via the query string.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Adam Bixby · textwebappsmultiple
https://www.exploit-db.com/exploits/33180
References (6)
Scores
EPSS
0.0975
EPSS Percentile
92.8%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
adobe/flex_sdk
< 3.4
n/a/n/a
Timeline
Published
Aug 21, 2009
Tracked Since
Feb 18, 2026