Lucene search

K
nvd[email protected]NVD:CVE-2008-6508
HistoryMar 23, 2009 - 8:00 p.m.

CVE-2008-6508

2009-03-2320:00:00
CWE-22
web.nvd.nist.gov

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.7 Medium

AI Score

Confidence

Low

0.665 Medium

EPSS

Percentile

97.9%

Directory traversal vulnerability in the AuthCheck filter in the Admin Console in Openfire 3.6.0a and earlier allows remote attackers to bypass authentication and access the admin interface via a … (dot dot) in a URI that matches the Exclude-Strings list, as demonstrated by a /setup/setup-/… sequence in a URI.

Affected configurations

NVD
Node
igniterealtimeopenfireRange3.6.0a
OR
igniterealtimeopenfireMatch2.6.0
OR
igniterealtimeopenfireMatch2.6.1
OR
igniterealtimeopenfireMatch2.6.2
OR
igniterealtimeopenfireMatch3.0.0
OR
igniterealtimeopenfireMatch3.0.1
OR
igniterealtimeopenfireMatch3.1.0
OR
igniterealtimeopenfireMatch3.1.1
OR
igniterealtimeopenfireMatch3.2.0
OR
igniterealtimeopenfireMatch3.2.1
OR
igniterealtimeopenfireMatch3.2.2
OR
igniterealtimeopenfireMatch3.2.3
OR
igniterealtimeopenfireMatch3.2.4
OR
igniterealtimeopenfireMatch3.3.0
OR
igniterealtimeopenfireMatch3.3.2
OR
igniterealtimeopenfireMatch3.3.3
OR
igniterealtimeopenfireMatch3.4.0
OR
igniterealtimeopenfireMatch3.4.1
OR
igniterealtimeopenfireMatch3.4.3
OR
igniterealtimeopenfireMatch3.4.4
OR
igniterealtimeopenfireMatch3.4.5
OR
igniterealtimeopenfireMatch3.5.0
OR
igniterealtimeopenfireMatch3.5.1
OR
igniterealtimeopenfireMatch3.5.2
OR
igniterealtimeopenfireMatch3.6.0

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.7 Medium

AI Score

Confidence

Low

0.665 Medium

EPSS

Percentile

97.9%