Atlassian Jira Improper Control of Generation of Code (Code Injection) Vulnerability - CVE-2008-6531 - Vulnerability Database

Atlassian Jira Improper Control of Generation of Code (Code Injection) Vulnerability - CVE-2008-6531

Medium
Reference: CVE-2008-6531
Title: Atlassian Jira Improper Control of Generation of Code (Code Injection) Vulnerability
Overview:

The WebWork 1 web application framework in Atlassian JIRA before 3.13.2 allows remote attackers to invoke exposed public JIRA methods via a crafted URL that is dynamically transformed into method calls aka quotWebWork 1 Parameter Injection Hole.quot