CVE-2010-1164

EXPLOITED IN THE WILD

Atlassian JIRA 3.12-4.1 - Cross-Site Scripting via Multiple Input Parameters

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2010-1164 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io).

Description

Multiple cross-site scripting (XSS) vulnerabilities in Atlassian JIRA 3.12 through 4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) element or (2) defaultColor parameter to the Colour Picker page; the (3) formName parameter, (4) element parameter, or (5) full name field to the User Picker page; the (6) formName parameter, (7) element parameter, or (8) group name field to the Group Picker page; the (9) announcement_preview_banner_st parameter to unspecified components, related to the Announcement Banner Preview page; unspecified vectors involving the (10) groupnames.jsp, (11) indexbrowser.jsp, (12) classpath-debug.jsp, (13) viewdocument.jsp, or (14) cleancommentspam.jsp page; the (15) portletKey parameter to runportleterror.jsp; the (16) URI to issuelinksmall.jsp; the (17) afterURL parameter to screenshot-redirecter.jsp; or the (18) HTTP Referrer header to 500page.jsp, as exploited in the wild in April 2010.

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/57827
Vendor Advisory x_refsource_confirm
http://jira.atlassian.com/browse/JRA-20994
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/57826
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2010/04/16/3
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2010/04/16/4
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39353
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/39485
Patch, Vendor Advisory x_refsource_confirm
http://jira.atlassian.com/browse/JRA-21004

Scores

EPSS 0.0057
EPSS Percentile 68.8%

Details

VulnCheck KEV 2010-04-20
InTheWild.io 2017-08-17
CWE
CWE-79
Status published
Products (14)
atlassian/jira 3.12
atlassian/jira 3.12.1
atlassian/jira 3.12.2
atlassian/jira 3.12.3
atlassian/jira 3.13
atlassian/jira 3.13.1
atlassian/jira 3.13.2
atlassian/jira 3.13.3
atlassian/jira 3.13.4
atlassian/jira 3.13.5
... and 4 more
Published Apr 20, 2010
Tracked Since Feb 18, 2026