CVE-2018-13393
https://notcve.org/view.php?id=CVE-2018-13393
The convertCommentToAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed version in Confluence version 6.9.0, allows remote attackers to modify a comment into an answer via a Cross-site request forgery (CSRF) vulnerability. El recurso convertCommentToAnswer en Atlassian Confluence Questions en versiones anteriores a la 2.6.6, la versión empaquetada de Confluence Questions se actualizó a una versión arreglada en Confluence 6.9.0, permite que los atacantes remotos modifiquen un comentario en una respuesta mediante una vulnerabilidad Cross-Site Request Forgery (CSRF). • http://www.securityfocus.com/bid/105155 https://jira.atlassian.com/browse/CONFSERVER-56282 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2018-13389
https://notcve.org/view.php?id=CVE-2018-13389
The attachment resource in Atlassian Confluence before version 6.6.1 allows remote attackers to spoof web content in the Mozilla Firefox Browser through attachments that have a content-type of application/rdf+xml. El recurso attachment en Atlassian Confluence en versiones anteriores a la 6.6.1 permite que atacantes remotos suplanten el contenido web en el navegador Mozilla Firefox mediante adjuntos que tienen un tipo de contenido de application/rdf+xml. • http://www.securityfocus.com/bid/104755 https://jira.atlassian.com/browse/CONFSERVER-54906 • CWE-20: Improper Input Validation •
CVE-2017-18086
https://notcve.org/view.php?id=CVE-2017-18086
Various resources in Atlassian Confluence Server before version 6.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuesURL parameter. Varios recursos en Atlassian Confluence Server, en versiones anteriores a la 6.4.2, permiten que atacantes remotos inyecten HTML o JavaScript arbitrario mediante una vulnerabilidad Cross-Site Scripting (XSS) en el parámetro issuesURL. • http://www.securityfocus.com/bid/103061 https://jira.atlassian.com/browse/CONFSERVER-54907 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2017-18084
https://notcve.org/view.php?id=CVE-2017-18084
The usermacros resource in Atlassian Confluence Server before version 6.3.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the description of a macro. El recurso usermacros en Atlassian Confluence Server, en versiones anteriores a la 6.3.4, permite que atacantes remotos inyecten HTML o JavaScript arbitrario mediante una vulnerabilidad Cross-Site Scripting (XSS) a través de la descripción de una macro. • http://www.securityfocus.com/bid/103064 https://jira.atlassian.com/browse/CONFSERVER-54904 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2017-18083
https://notcve.org/view.php?id=CVE-2017-18083
The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of an uploaded file. El recurso editinword en Atlassian Confluence Server, en versiones anteriores a la 6.4.0, permite que atacantes remotos inyecten HTML o JavaScript arbitrario mediante una vulnerabilidad Cross-Site Scripting (XSS) a través del contenido de un archivo subido. • https://jira.atlassian.com/browse/CONFSERVER-54903 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •