Cross-site scripting (XSS) vulnerability in Adobe Experience Manager (AEM) 6.1.0 allows remote authenticated users to inject arbitrary web script or HTML via a folder title field that is mishandled in the Deletion popup dialog.
https://helpx.adobe.com/security/products/experience-manager/apsb16-05.html
http://www.csnc.ch/misc/files/advisories/CVE-2016-0955_AEM-XSS.txt