PT-2005-4705 · Atlassian · Confluence

Publicado

2005-12-03

·

Atualizado

2011-03-08

·

CVE-2005-3967

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Atlassian Confluence version 2.0.1 Build 321
Description A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML. This is achieved via the searchQuery.queryString parameter in the dosearchsite.action module.
Recommendations For Atlassian Confluence version 2.0.1 Build 321, consider restricting access to the dosearchsite.action module until a fix is available. As a temporary workaround, avoid using the searchQuery.queryString parameter in the affected module to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-3967

Produtos afetados

Confluence