Page 10 of 63 results (0.012 seconds)

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

The acceptAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed version in Confluence version 6.9.0, allows remote attackers to modify a comment into an answer via a Cross-site request forgery (CSRF) vulnerability. El recurso acceptAnswer en Atlassian Confluence Questions en versiones anteriores a la 2.6.6, la versión empaquetada de Confluence Questions se actualizó a una versión arreglada en Confluence 6.9.0, permite que los atacantes remotos modifiquen un comentario en una respuesta mediante una vulnerabilidad Cross-Site Request Forgery (CSRF). • http://www.securityfocus.com/bid/105284 https://jira.atlassian.com/browse/CONFSERVER-56283 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 4.7EPSS: 0%CPEs: 1EXPL: 0

The attachment resource in Atlassian Confluence before version 6.6.1 allows remote attackers to spoof web content in the Mozilla Firefox Browser through attachments that have a content-type of application/rdf+xml. El recurso attachment en Atlassian Confluence en versiones anteriores a la 6.6.1 permite que atacantes remotos suplanten el contenido web en el navegador Mozilla Firefox mediante adjuntos que tienen un tipo de contenido de application/rdf+xml. • http://www.securityfocus.com/bid/104755 https://jira.atlassian.com/browse/CONFSERVER-54906 • CWE-20: Improper Input Validation •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

Various resources in Atlassian Confluence Server before version 6.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuesURL parameter. Varios recursos en Atlassian Confluence Server, en versiones anteriores a la 6.4.2, permiten que atacantes remotos inyecten HTML o JavaScript arbitrario mediante una vulnerabilidad Cross-Site Scripting (XSS) en el parámetro issuesURL. • http://www.securityfocus.com/bid/103061 https://jira.atlassian.com/browse/CONFSERVER-54907 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.8EPSS: 0%CPEs: 1EXPL: 0

The usermacros resource in Atlassian Confluence Server before version 6.3.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the description of a macro. El recurso usermacros en Atlassian Confluence Server, en versiones anteriores a la 6.3.4, permite que atacantes remotos inyecten HTML o JavaScript arbitrario mediante una vulnerabilidad Cross-Site Scripting (XSS) a través de la descripción de una macro. • http://www.securityfocus.com/bid/103064 https://jira.atlassian.com/browse/CONFSERVER-54904 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 0

The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of an uploaded file. El recurso editinword en Atlassian Confluence Server, en versiones anteriores a la 6.4.0, permite que atacantes remotos inyecten HTML o JavaScript arbitrario mediante una vulnerabilidad Cross-Site Scripting (XSS) a través del contenido de un archivo subido. • https://jira.atlassian.com/browse/CONFSERVER-54903 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •