Description
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to rest/prototype/1/session/check.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2008-0347 Vulnerability (CVE-2008-0347)
WordPress Plugin Windsor Strava Athlete Unspecified Vulnerability (1.3.5)
WordPress Plugin Media Library Assistant Information Disclosure (3.00)
Internet Information Services Other Vulnerability (CVE-2000-0408)
WordPress Plugin Campaign URL Builder Cross-Site Request Forgery (1.5.0)