Jira Rainbow.Zen contains a cross-site scripting vulnerability via Jira/secure/BrowseProject.jspa which allows remote attackers to inject arbitrary web script or HTML via the id parameter.
id: CVE-2007-0885
info:
name: Jira Rainbow.Zen - Cross-Site Scripting
author: geeknik
severit
...