CVE-2008-6510

Igniterealtime Openfire < 3.6.0a - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in login.jsp in the Admin Console in Openfire 3.6.0a and earlier allows remote attackers to inject arbitrary web script or HTML via the url parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Andreas Kurtz · textwebappsjsp
https://www.exploit-db.com/exploits/7075

Scores

EPSS 0.0538
EPSS Percentile 90.0%

Classification

CWE
CWE-79
Status published

Affected Products (26)

igniterealtime/openfire < 3.6.0a
igniterealtime/openfire
igniterealtime/openfire
igniterealtime/openfire
igniterealtime/openfire
igniterealtime/openfire
igniterealtime/openfire
igniterealtime/openfire
igniterealtime/openfire
igniterealtime/openfire
igniterealtime/openfire
igniterealtime/openfire
igniterealtime/openfire
igniterealtime/openfire
igniterealtime/openfire
... and 11 more

Timeline

Published Mar 23, 2009
Tracked Since Feb 18, 2026