Description
Various resources in Atlassian Confluence Server before version 6.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuesURL parameter.
Remediation
References
Related Vulnerabilities
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-0866)
WordPress Plugin Backup and Restore WordPress-WPBackItUp Cross-Site Request Forgery (1.6.7)
Oracle Database Server CVE-2009-3411 Vulnerability (CVE-2009-3411)
WordPress Plugin WordPress Landing Pages Cross-Site Scripting (1.8.5)