Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) log parameter to (a) logviewer.jsp and (b) log.jsp; (2) search parameter to (c) group-summary.jsp; (3) username parameter to (d) user-properties.jsp; (4) logDir, (5) maxTotalSize, (6) maxFileSize, (7) maxDays, and (8) logTimeout parameters to (e) audit-policy.jsp; (9) propName parameter to (f) server-properties.jsp; and the (10) roomconfig_roomname and (11) roomconfig_roomdesc parameters to (g) muc-room-edit-form.jsp. NOTE: this can be leveraged for arbitrary code execution by using XSS to upload a malicious plugin.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ignite Realtime | Openfire | 3.6.2 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/33452Vendor Advisory
- http://www.coresecurity.com/content/openfire-multiple-vulnerabilitiesExploit
- http://www.igniterealtime.org/issues/browse/JM-1506
- http://www.securityfocus.com/archive/1/499880/100/0/threaded
- http://www.securityfocus.com/bid/32935
- http://www.securityfocus.com/bid/32937Exploit
- http://www.securityfocus.com/bid/32938Exploit
- http://www.securityfocus.com/bid/32939
- http://www.securityfocus.com/bid/32940Exploit
- http://www.securityfocus.com/bid/32943
- http://www.securityfocus.com/bid/32944
- https://bugs.gentoo.org/show_bug.cgi?id=254309
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47834
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47835
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47845
FAQ
What is CVE-2009-0496?
CVE-2009-0496 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) log parameter to (a) logviewer.jsp and (...
How severe is CVE-2009-0496?
CVE-2009-0496 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-0496?
Check the references section above for vendor advisories and patch information. Affected products include: Ignite Realtime Openfire.