info
discussion
exploit
solution
references
Atlassian Confluence Search Cross-Site Scripting Vulnerability
References:
Atlassian Confluence Web Site
(Atlassian)
Confluence - the Enterprise Wiki, XSS vuln.
(r0t)
Confluence Security Advisory 2005-12-05
(Atlassian)
Search results page needs to XML encode the query string provided by the user.
(Atlassian)
Privacy Statement
Copyright 2010, SecurityFocus