Description
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitrary web script or HTML via the newFileName parameter to pages/doeditattachment.action.
Remediation
References
Related Vulnerabilities
WordPress Plugin Broken Link Checker Cross-Site Scripting (1.10.4)
phpList Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2008-6178)
WordPress Plugin Contact Form Email Cross-Site Scripting (1.1.47)
WordPress Plugin Front-end Editor 'upload.php' Arbitrary File Upload (2.2.1)
WordPress Plugin WooCommerce OpenPOS Arbitrary File Deletion (6.4.4)