This application requires Javascript for optimal performance.

Jive.Openfire.User.Properties.XSS

Release Date

Mar 05, 2009

Severity

high

Impact

System Compromise: Remote attackers can inject commands.

Description

This indicates an attack attempt against an XSS-vulnerability in Openfire software.

The vulnerability is caused by an error when the vulnerable software handles user-properties.jsp. It allows a remote attacker to perform command injection via sending a crafted web page.

Affected Products

Openfire 3.6.2

Recommended Actions

Update to latest version Openfire 3.6.3

Coverage

IPS
VCM

Reference/s

http://www.securityfocus.com/bid/32938 (BugTraq)

Reference: VID-17093