Show filters
70 Total Results
Displaying 61-70 of 70
Sort by:
Attacker Value
Unknown

CVE-2017-7415

Disclosure Date: April 27, 2017 (last updated November 26, 2024)
Atlassian Confluence 6.x before 6.0.7 allows remote attackers to bypass authentication and read any blog or page via the drafts diff REST resource.
0
Attacker Value
Unknown

CVE-2016-4317

Disclosure Date: April 10, 2017 (last updated November 26, 2024)
Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page.
0
Attacker Value
Unknown

CVE-2016-6668

Disclosure Date: January 23, 2017 (last updated November 25, 2024)
The Atlassian Hipchat Integration Plugin for Bitbucket Server 6.26.0 before 6.27.5, 6.28.0 before 7.3.7, and 7.4.0 before 7.8.17; Confluence HipChat plugin 6.26.0 before 7.8.17; and HipChat for JIRA plugin 6.26.0 before 7.8.17 allows remote attackers to obtain the secret key for communicating with HipChat instances by reading unspecified pages.
Attacker Value
Unknown

CVE-2016-6283

Disclosure Date: January 18, 2017 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitrary web script or HTML via the newFileName parameter to pages/doeditattachment.action.
0
Attacker Value
Unknown

CVE-2015-8399

Disclosure Date: April 11, 2016 (last updated November 25, 2024)
Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdefaultdecorator.action or (2) admin/viewdefaultdecorator.action.
0
Attacker Value
Unknown

CVE-2015-8398

Disclosure Date: April 11, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to rest/prototype/1/session/check.
0
Attacker Value
Unknown

CVE-2012-6342

Disclosure Date: May 13, 2014 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in logout.action in Atlassian Confluence 3.4.6 allows remote attackers to hijack the authentication of administrators for requests that logout the user via a comment.
0
Attacker Value
Unknown

CVE-2012-2926

Disclosure Date: May 22, 2012 (last updated October 04, 2023)
Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo before 3.3.4 and 3.4.x before 3.4.5; and Crowd before 2.0.9, 2.1 before 2.1.2, 2.2 before 2.2.9, 2.3 before 2.3.7, and 2.4 before 2.4.1 do not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.
Attacker Value
Unknown

CVE-2012-2928

Disclosure Date: May 22, 2012 (last updated October 04, 2023)
The Gliffy plugin before 3.7.1 for Atlassian JIRA, and before 4.2 for Atlassian Confluence, does not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.
0
Attacker Value
Unknown

CVE-2005-3967

Disclosure Date: December 03, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the dosearchsite.action module in Atlassian Confluence 2.0.1 Build 321 allows remote attackers to inject arbitrary web script or HTML via the searchQuery.queryString search module parameter.
0