Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows remote attackers to execute arbitrary code by uploading a Java Archive (.jsp) file during a PUBLISH action, then accessing it via a direct request to the file in the robohelp/robo/reserved/web directory under its sessionid subdirectory, as demonstrated by the vd_adobe module in VulnDisco Pack Professional 8.7 through 8.11.
Use CWE-264, Adobe vendor hub and Robohelp Server product page to widen CVE-2009-3068 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-30670, CVE-2021-28588 and CVE-2021-42727 for nearby disclosures in the same product family.