vendor:
Openfire Server
by:
Andreas Kurtz
3.3
CVSS
LOW
Authentication Bypass, SQL Injection, Cross-Site Scripting
287, 89, 79
CWE
Product Name: Openfire Server
Affected Version From: Openfire Server <= 3.6.0a
Affected Version To: Openfire Server <= 3.6.0a
Patch Exists: NO
Related CWE: N/A
CPE: a:igniterealtime:openfire
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Openfire Server Multiple Vulnerabilities
The jabber server Openfire (<= version 3.6.0a) contains several serious vulnerabilities. Depending on the particular runtime environment these issues can potentially even be used by an attacker to execute code on operating system level. Authentication to the openfire admin interface is secured by a filter in the Tomcat application server (org.jivesoftware.admin.AuthCheckFilter). This filter guarantees that access to the admin interface is only granted to authenticated users. The filter can be bypassed by manipulating the URL. The vulnerability is located in the 'search.jsp' file for SQL injection and 'login.jsp' file for Cross-Site Scripting.
Mitigation:
No patch released yet.