CVE-2008-6511 EXPLOIT
5.8
MEDIUM · CVSS 2.0 · EPSS 1.8% (pctl 78)
Patch early
A public exploit exists.
Description
Open redirect vulnerability in login.jsp in Openfire 3.6.0a and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter.
Scoring
| CVSS | 5.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:P |
| EPSS | 1.83% — more likely to be exploited than 78% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-03-23 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| igniterealtime | openfire |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Openfire Server 3.6.0a - Authentication Bypass / SQL Injection / Cross-Site Scripting | 2008-11-09 |
References
- http://www.andreas-kurtz.de/advisories/AKADV2008-001-v1.0.txt
- http://www.securityfocus.com/archive/1/498162/100/0/threaded
- https://www.exploit-db.com/exploits/7075
- http://www.andreas-kurtz.de/advisories/AKADV2008-001-v1.0.txt
- http://www.securityfocus.com/archive/1/498162/100/0/threaded
- https://www.exploit-db.com/exploits/7075
→ the Explorer · watch your stack · NVD