History
Log In
h
ome
b
rowse project
f
ind issues
p
lanning board
t
ask board
Q
uick Search:
Learn more about
Quick Search
New and Improved 3.13 Beta.
Highlights: Shareable filters and dashboards and
lots of other goodies
. Any feedback can be raised as JIRA issues in the JIRA project.
Issue Details
(
XML
|
Word
|
Printable
)
Key:
CONF-8951
Type:
Bug
Status:
Closed
Resolution:
Duplicate
Priority:
Critical
Assignee:
Unassigned
Reporter:
Gergely Hodicska
Votes:
2
Watchers:
1
Operations
If you were
logged in
you would be able to see more operations.
Confluence
XSS vulnerability in app/spaces/editspace.action
Created:
19/Jul/07 07:49 AM
Updated:
25/Jul/07 09:25 PM
Component/s:
Security
,
Spaces
Affects Version/s:
2.5.4
Fix Version/s:
2.5.6
Time Tracking:
Not Specified
Environment:
Standalone
Issue Links:
Duplicate
This issue
duplicates
:
CONF-8917
XSS vulnerability: space name and key not validated nor escaped
Participants:
Gergely Hodicska
Since last comment:
1 year, 5 weeks, 6 days ago
Resolution Date:
25/Jul/07 09:25 PM
Labels:
Description
« Hide
Description:
XSS via the "Name" field in app/spaces/editspace.action.
Exploit:
blah"><script>alert(document.cookie)</script><x x="
Description
Description: XSS via the "Name" field in app/spaces/editspace.action. Exploit: blah"><script>alert(document.cookie)</script><x x="
Show »
All
Comments
Work Log
Change History
Sort Order:
There are no comments yet on this issue.