FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2009-0497

This CVE name corresponds to:

Entered Topic
2009-01-25 openfire -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2009-0497
Phase Assigned(20090209)

Description

Directory traversal vulnerability in log.jsp in Ignite Realtime Openfire 3.6.2 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the log parameter.

References

Source Reference
BUGTRAQ 20090108 CORE-2008-1128: Openfire multiple vulnerabilities
MISC http://svn.igniterealtime.org/svn/repos/openfire/trunk/src/web/log.jsp
MISC http://www.coresecurity.com/content/openfire-multiple-vulnerabilities
MISC https://bugs.gentoo.org/show_bug.cgi?id=257585
BID 32945
SECUNIA 33452
XF openfire-log-directory-traversal(47806)