Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2009-0496
StatusCandidate
DescriptionMultiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) log parameter to (a) logviewer.jsp and (b) log.jsp; (2) search parameter to (c) group-summary.jsp; (3) username parameter to (d) user-properties.jsp; (4) logDir, (5) maxTotalSize, (6) maxFileSize, (7) maxDays, and (8) logTimeout parameters to (e) audit-policy.jsp; (9) propName parameter to (f) server-properties.jsp; and the (10) roomconfig_roomname and (11) roomconfig_roomdesc parameters to (g) muc-room-edit-form.jsp.  NOTE: this can be leveraged for arbitrary code execution by using XSS to upload a malicious plugin.
SeverityMedium
CVSS score4,3
CVSS vector(AV:N/AC:M/Au:N/C:N/I:P/A:N)
PhaseAssigned (10.02.2009)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0496
ReferencesBID : 32935
 BID : 32937
 BID : 32938
 BID : 32939
 BID : 32940
 BID : 32943
 BID : 32944
 BUGTRAQ : 20090108 CORE-2008-1128: Openfire multiple vulnerabilities
 CONFIRM : http://www.igniterealtime.org/issues/browse/JM-1506
 CONFIRM : https://bugs.gentoo.org/show_bug.cgi?id=254309
 MISC : http://www.coresecurity.com/content/openfire-multi...
 SECUNIA : 33452
 XF : openfire-mucroomeditform-xss(47845)
 XF : openfire-multiple-scripts-xss(47834)
 XF : openfire-serverproperties-xss(47835)
SecurityVulns:Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server