Description
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitrary web script or HTML via the newFileName parameter to pages/doeditattachment.action.
Remediation
References
Related Vulnerabilities
WordPress Plugin ALO EasyMail Newsletter Cross-Site Request Forgery (2.6.01)
MODX Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-8775)
WordPress Plugin Controlled Admin Access Security Bypass (1.5.5)
Dotclear Improper Access Control Vulnerability (CVE-2015-8832)
WordPress Plugin NextGEN Gallery-WordPress Gallery 'nggallery-manage-gallery' HTML Injection (0.96)