33452Third-party advisory
http://secunia.com/advisories/33452 CVE-2009-0497
Openfire 3.6.2 - 'log.jsp' Directory Traversal
Record summary
CVE-2009-0497 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
Directory traversal vulnerability in log.jsp in Ignite Realtime Openfire 3.6.2 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the log parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBOpenfire 3.6.2 - 'log.jsp' Directory TraversalExploitDB exploitby Federico MuttisNot analyzed1 file
References
8svn.igniterealtime.org
http://svn.igniterealtime.org/svn/repos/openfire/trunk/src/web/log.jsp coresecurity.com
http://www.coresecurity.com/content/openfire-multiple-vulnerabilities 20090108 CORE-2008-1128: Openfire multiple vulnerabilitiesmailing list
http://www.securityfocus.com/archive/1/499880/100/0/threaded 32945vdb entry
http://www.securityfocus.com/bid/32945 bugs.gentoo.org
https://bugs.gentoo.org/show_bug.cgi?id=257585 openfire-log-directory-traversal(47806)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/47806 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2009-0497