Lucene search

K
cve[email protected]CVE-2008-6508
HistoryMar 23, 2009 - 8:00 p.m.

CVE-2008-6508

2009-03-2320:00:00
CWE-22
web.nvd.nist.gov
48
In Wild
cve-2008-6508
directory traversal
authcheck filter
admin console
openfire 3.6.0a
security vulnerability

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.4 High

AI Score

Confidence

High

0.665 Medium

EPSS

Percentile

97.9%

Directory traversal vulnerability in the AuthCheck filter in the Admin Console in Openfire 3.6.0a and earlier allows remote attackers to bypass authentication and access the admin interface via a … (dot dot) in a URI that matches the Exclude-Strings list, as demonstrated by a /setup/setup-/… sequence in a URI.

Affected configurations

NVD
Node
igniterealtimeopenfireRange3.6.0a
OR
igniterealtimeopenfireMatch2.6.0
OR
igniterealtimeopenfireMatch2.6.1
OR
igniterealtimeopenfireMatch2.6.2
OR
igniterealtimeopenfireMatch3.0.0
OR
igniterealtimeopenfireMatch3.0.1
OR
igniterealtimeopenfireMatch3.1.0
OR
igniterealtimeopenfireMatch3.1.1
OR
igniterealtimeopenfireMatch3.2.0
OR
igniterealtimeopenfireMatch3.2.1
OR
igniterealtimeopenfireMatch3.2.2
OR
igniterealtimeopenfireMatch3.2.3
OR
igniterealtimeopenfireMatch3.2.4
OR
igniterealtimeopenfireMatch3.3.0
OR
igniterealtimeopenfireMatch3.3.2
OR
igniterealtimeopenfireMatch3.3.3
OR
igniterealtimeopenfireMatch3.4.0
OR
igniterealtimeopenfireMatch3.4.1
OR
igniterealtimeopenfireMatch3.4.3
OR
igniterealtimeopenfireMatch3.4.4
OR
igniterealtimeopenfireMatch3.4.5
OR
igniterealtimeopenfireMatch3.5.0
OR
igniterealtimeopenfireMatch3.5.1
OR
igniterealtimeopenfireMatch3.5.2
OR
igniterealtimeopenfireMatch3.6.0

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.4 High

AI Score

Confidence

High

0.665 Medium

EPSS

Percentile

97.9%