Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2009-1595
Description:The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a passwd_change action.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2009-1595
BugTraq ID: 34804
http://www.securityfocus.com/bid/34804
http://osvdb.org/54189
http://secunia.com/advisories/34976
http://www.vupen.com/english/advisories/2009/1237
XForce ISS Database: openfire-jabberiqauth-security-bypass(50292)
https://exchange.xforce.ibmcloud.com/vulnerabilities/50292




© 1998-2025 E-Soft Inc. All rights reserved.