Description:
XSS via the "Filter By File Extension" field in app/spaces/listattachmentforspace.action.
Exploit:
blah"><script>alert(document.cookie)</script><x x="
- was cloned as
-
CONFSERVER-8952 XSS vulnerability in app/pages/listpages-alphaview.action
-
- Closed
-
Hi Christopher,
I agree with Igor: few weeks seems a little too much to fix these bugs. I am not familiar devloping in JAVA, but this is only a small escaping/filtering issue.
In enterprise enviroment this bugs can be very easily exploited, bacuase people rely on eachother.