CVE-2008-6509: SQL Injection
SQL injection vulnerability in CallLogDAO in SIP Plugin in Openfire 3.6.0a and earlier allows remote attackers to execute arbitrary SQL commands via the type parameter to sipark-log-summary.jsp.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-6509?
CVE-2008-6509 is considered a high severity vulnerability due to its ability to allow remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2008-6509?
To fix CVE-2008-6509, upgrade Openfire to version 3.6.0b or later where the vulnerability has been patched.
What software versions are affected by CVE-2008-6509?
CVE-2008-6509 affects Openfire versions 3.6.0 and earlier, including several specific earlier versions.
What is the nature of the vulnerability in CVE-2008-6509?
CVE-2008-6509 is an SQL injection vulnerability that allows attackers to manipulate database queries through an insecure parameter.
Can CVE-2008-6509 be exploited remotely?
Yes, CVE-2008-6509 can be exploited remotely without any authentication, making it particularly dangerous.