Page 10 of 46 results (0.004 seconds)

CVSS: 4.3EPSS: 0%CPEs: 56EXPL: 0

Multiple cross-site scripting (XSS) vulnerabilities in the user profile feature in Atlassian FishEye before 2.5.5 allow remote attackers to inject arbitrary web script or HTML via (1) snippets in a user comment, which is not properly handled in a Confluence page, or (2) the user profile display name, which is not properly handled in a FishEye page. Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en la funcionalidad de perfil de usuario de Atlassian FishEye en versiones anteriores a 2.5.5. Permite a usuarios remotos inyectar codigo de script web o código HTML de su elección a través de (1) "snippets" en un comentario de usuario, que no son manejados apropiadamente en una página Confluence, o (2) el nombre para mostrar del perfil de usuario, que no es apropiadamente procesado en una página FishEye. • http://confluence.atlassian.com/display/FISHEYE/FishEye+and+Crucible+Security+Advisory+2011-11-22 http://osvdb.org/77263 http://osvdb.org/77264 http://secunia.com/advisories/46975 http://www.securityfocus.com/bid/50762 https://exchange.xforce.ibmcloud.com/vulnerabilities/71426 https://exchange.xforce.ibmcloud.com/vulnerabilities/71427 https://jira.atlassian.com/browse/FE-3797 https://jira.atlassian.com/browse/FE-3798 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •