Openfire 3.10.2 - Multiple Vulnerabilities

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Product: Openfire 3.10.2 Openfire is a real time collaboration (RTC) server licensed under the Open Source Apache License. It uses the only widely adopted open protocol for instant messaging, XMPP (also called Jabber). #### Vulnerability Type: Unrestricted File Upload #### Vulnerability Details: Application specifies Plugin files (.jar) can be uploaded directly by using the form, however so can the following. ``` .exe .php .jsp .py .sh ``` #### Exploit code(s): * 1) choose some malicious file using the File browser * 2) click 'upload plugin' ``` http://localhost:9090/plugin-admin.jsp ``` Our malicious uploaded files will be stored under `/openfire/plugins` directory. #### Description: ``` Request Method(s): [+] POST Vulnerable Product: [+] Openfire 3.10.2 Vulnerable Parameter(s): [+] fileName Affected Area(s): [+] Server ``` ---------------------------------------------------------------------- ### Openfire 3.10.2 - Remote File Inclusion Openfire is a real time collaboration...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息