CVE-2008-6510: XSS
Cross-site scripting (XSS) vulnerability in login.jsp in the Admin Console in Openfire 3.6.0a and earlier allows remote attackers to inject arbitrary web script or HTML via the url parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-6510?
CVE-2008-6510 is classified as a medium severity vulnerability due to its potential to allow cross-site scripting attacks.
How do I fix CVE-2008-6510?
To fix CVE-2008-6510, upgrade to Openfire version 3.6.1 or later, which includes a patch for this vulnerability.
What software is affected by CVE-2008-6510?
CVE-2008-6510 affects Openfire versions 3.6.0a and earlier, including a range of versions from 2.6.0 to 3.6.0.
What kind of attack is possible with CVE-2008-6510?
CVE-2008-6510 allows remote attackers to perform cross-site scripting (XSS) attacks, injecting arbitrary web scripts or HTML.
Is there a workaround for CVE-2008-6510?
There is no known workaround for CVE-2008-6510; the only solution is to upgrade to the fixed version.