PT-2009-3150 · Ignite Realtime · Openfire
Eray Aslan
·
Published
2009-02-10
·
Updated
2018-10-11
·
CVE-2009-0497
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Openfire version 3.6.2
Description
A directory traversal issue exists in log.jsp, allowing remote attackers to read arbitrary files by providing a .. (dot dot backslash) in the
log parameter.Recommendations
For Openfire version 3.6.2, update to a version that fixes this issue, as using a .. (dot dot backslash) in the
log parameter of the log.jsp file can allow remote attackers to read arbitrary files.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openfire