Vulnerabilities
Vulnerable Software
Atlassian:  >> Fisheye  >> 2.10.6  Security Vulnerabilities
The review file upload resource in Atlassian Crucible before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the charset of a previously uploaded file.
CVSS Score
5.4
EPSS Score
0.003
Published
2017-08-24
The repository changelog resource in Atlassian Fisheye before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the start date and end date parameters.
CVSS Score
5.4
EPSS Score
0.003
Published
2017-08-24
The mostActiveCommitters.do resource in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to access sensitive information, for example email addresses of committers, as it lacked permission checks.
CVSS Score
7.5
EPSS Score
0.016
Published
2017-08-24


Contact Us

Shodan ® - All rights reserved