CVE Database
/

CVE-2009-0496

Back to search

CVE-2009-0496

Published: Feb 10, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) log parameter to (a) logviewer.jsp and (b) log.jsp; (2) search parameter to (c) group-summary.jsp; (3) username parameter to (d) user-properties.jsp; (4) logDir, (5) maxTotalSize, (6) maxFileSize, (7) maxDays, and (8) logTimeout parameters to (e) audit-policy.jsp; (9) propName parameter to (f) server-properties.jsp; and the (10) roomconfig_roomname and (11) roomconfig_roomdesc parameters to (g) muc-room-edit-form.jsp. NOTE: this can be leveraged for arbitrary code execution by using XSS to upload a malicious plugin.

VendorProductVersions

n/a

n/a

affected
n/a

References

32943
vdb-entry
x_refsource_BID
32940
vdb-entry
x_refsource_BID
32944
vdb-entry
x_refsource_BID
33452
third-party-advisory
x_refsource_SECUNIA
32935
vdb-entry
x_refsource_BID
32939
vdb-entry
x_refsource_BID
32938
vdb-entry
x_refsource_BID
32937
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now