Description
The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of an uploaded file.
Remediation
References
Related Vulnerabilities
WordPress Plugin Contact Form Check Tester Cross-Site Scripting (1.0.2)
WordPress Plugin Catch Infinite Scroll Security Bypass (1.8.1)
Oracle JRE CVE-2014-0432 Vulnerability (CVE-2014-0432)
WordPress Configuration Vulnerability (CVE-2009-2335)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-9854)