Lucene search

K
cvelistMitreCVELIST:CVE-2008-6508
HistoryMar 23, 2009 - 7:26 p.m.

CVE-2008-6508

2009-03-2319:26:00
mitre
www.cve.org
1

8.5 High

AI Score

Confidence

High

0.665 Medium

EPSS

Percentile

97.9%

Directory traversal vulnerability in the AuthCheck filter in the Admin Console in Openfire 3.6.0a and earlier allows remote attackers to bypass authentication and access the admin interface via a … (dot dot) in a URI that matches the Exclude-Strings list, as demonstrated by a /setup/setup-/… sequence in a URI.

8.5 High

AI Score

Confidence

High

0.665 Medium

EPSS

Percentile

97.9%