Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2009-1596
Description:Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which allows remote authenticated users to bypass intended policy and change their own passwords via a passwd_change IQ packet.
Test IDs: 1.3.6.1.4.1.25623.1.0.63943  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2009-1596
BugTraq ID: 34804
http://www.securityfocus.com/bid/34804
http://www.osvdb.org/54189
http://secunia.com/advisories/34984
XForce ISS Database: openfire-nopassword-security-bypass(50291)
https://exchange.xforce.ibmcloud.com/vulnerabilities/50291




© 1998-2025 E-Soft Inc. All rights reserved.