First published: Mon Mar 23 2009(Updated: )
SQL injection vulnerability in CallLogDAO in SIP Plugin in Openfire 3.6.0a and earlier allows remote attackers to execute arbitrary SQL commands via the type parameter to sipark-log-summary.jsp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Openfire | =3.2.2 | |
Openfire | <=3.6.0a | |
Openfire | =3.0.0 | |
Openfire | =3.0.1 | |
Openfire | =3.2.1 | |
Openfire | =3.4.4 | |
Openfire | =3.1.0 | |
Openfire | =3.4.0 | |
Openfire | =3.6.0 | |
Openfire | =3.2.3 | |
Openfire | =3.4.5 | |
Openfire | =3.3.2 | |
Openfire | =3.2.0 | |
Openfire | =3.5.0 | |
Openfire | =3.4.3 | |
Openfire | =2.6.1 | |
Openfire | =2.6.0 | |
Openfire | =2.6.2 | |
Openfire | =3.1.1 | |
Openfire | =3.5.2 | |
Openfire | =3.3.3 | |
Openfire | =3.5.1 | |
Openfire | =3.2.4 | |
Openfire | =3.3.0 | |
Openfire | =3.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-6509 is considered a high severity vulnerability due to its ability to allow remote attackers to execute arbitrary SQL commands.
To fix CVE-2008-6509, upgrade Openfire to version 3.6.0b or later where the vulnerability has been patched.
CVE-2008-6509 affects Openfire versions 3.6.0 and earlier, including several specific earlier versions.
CVE-2008-6509 is an SQL injection vulnerability that allows attackers to manipulate database queries through an insecure parameter.
Yes, CVE-2008-6509 can be exploited remotely without any authentication, making it particularly dangerous.