Openfire Multiple Input Validation Vulnerabilities
BID:32189
Info
Openfire Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 32189 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6508 CVE-2008-6509 CVE-2008-6510 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 07 2008 12:00AM |
| Updated: | Mar 19 2015 09:37AM |
| Credit: | Andreas Kurtz |
| Vulnerable: |
Ignite Realtime Openfire 3.6.0a Gentoo Linux |
| Not Vulnerable: | |
Discussion
Openfire Multiple Input Validation Vulnerabilities
Openfire is prone to multiple input-validation vulnerabilities:
- An SQL-injection issue.
- Multiple cross-site scripting issues.
- An authentication-bypass issue.
A successful exploit of these issues may allow an attacker to gain unauthorized access to the affected application, compromise the application, access or modify data, exploit vulnerabilities in the underlying database, execute arbitrary script code within the context of the browser, and steal cookie-based authentication credentials. Other attacks are also possible.
Openfire 3.6.0a is vulnerable; other versions may also be affected.
Openfire is prone to multiple input-validation vulnerabilities:
- An SQL-injection issue.
- Multiple cross-site scripting issues.
- An authentication-bypass issue.
A successful exploit of these issues may allow an attacker to gain unauthorized access to the affected application, compromise the application, access or modify data, exploit vulnerabilities in the underlying database, execute arbitrary script code within the context of the browser, and steal cookie-based authentication credentials. Other attacks are also possible.
Openfire 3.6.0a is vulnerable; other versions may also be affected.
Exploit / POC
Openfire Multiple Input Validation Vulnerabilities
An attacker can exploit these issues through a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting user to follow a malicious URI.
The following example URIs and exploit code are available:
An attacker can exploit these issues through a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting user to follow a malicious URI.
The following example URIs and exploit code are available:
Solution / Fix
Openfire Multiple Input Validation Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Openfire Multiple Input Validation Vulnerabilities
References:
References:
- Openfire Homepage (Ignite Realtime)
- Openfire Server Multiple Vulnerabilities (Andreas Kurtz)
- [AK-ADV2008-001] Openfire Jabber-Server: Multiple Vulnerabilities (Authenticati (Andreas Kurtz
)