Description
The Gliffy plugin before 3.7.1 for Atlassian JIRA, and before 4.2 for Atlassian Confluence, does not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.
Remediation
References
Related Vulnerabilities
WordPress Plugin Media Library Assistant Information Disclosure (3.00)
Oracle Database Server CVE-2009-1992 Vulnerability (CVE-2009-1992)
Plone CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2012-5488)
WordPress Plugin MyThemeShop Theme/Plugin Updater Cross-Site Scripting (1.2.3)