![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2009-0497 |
Description: | Directory traversal vulnerability in log.jsp in Ignite Realtime Openfire 3.6.2 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the log parameter. |
Test IDs: | None available |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2009-0497 BugTraq ID: 32945 http://www.securityfocus.com/bid/32945 Bugtraq: 20090108 CORE-2008-1128: Openfire multiple vulnerabilities (Google Search) http://www.securityfocus.com/archive/1/499880/100/0/threaded http://svn.igniterealtime.org/svn/repos/openfire/trunk/src/web/log.jsp http://www.coresecurity.com/content/openfire-multiple-vulnerabilities https://bugs.gentoo.org/show_bug.cgi?id=257585 http://secunia.com/advisories/33452 XForce ISS Database: openfire-log-directory-traversal(47806) https://exchange.xforce.ibmcloud.com/vulnerabilities/47806 |