CyberSec.Space Logo
返回 CVE 浏览器

CVE-2008-6509

HIGH
7.5
CVSS Severity Score
EPSS Score0.0370%
EPSS Percentile23.35th
Published2009年3月23日
Last Modified2026年4月23日

Vulnerability Description

SQL injection vulnerability in CallLogDAO in SIP Plugin in Openfire 3.6.0a and earlier allows remote attackers to execute arbitrary SQL commands via the type parameter to sipark-log-summary.jsp.

Affected Platforms (CPE)

📦
Igniterealtime

Openfire

<= 3.6.0a
📦
Igniterealtime

Openfire

= 2.6.0
📦
Igniterealtime

Openfire

= 2.6.1
📦
Igniterealtime

Openfire

= 2.6.2
📦
Igniterealtime

Openfire

= 3.0.0
📦
Igniterealtime

Openfire

= 3.0.1
📦
Igniterealtime

Openfire

= 3.1.0
📦
Igniterealtime

Openfire

= 3.1.1
📦
Igniterealtime

Openfire

= 3.2.0
📦
Igniterealtime

Openfire

= 3.2.1
📦
Igniterealtime

Openfire

= 3.2.2
📦
Igniterealtime

Openfire

= 3.2.3
📦
Igniterealtime

Openfire

= 3.2.4
📦
Igniterealtime

Openfire

= 3.3.0
📦
Igniterealtime

Openfire

= 3.3.2
📦
Igniterealtime

Openfire

= 3.3.3
📦
Igniterealtime

Openfire

= 3.4.0
📦
Igniterealtime

Openfire

= 3.4.1
📦
Igniterealtime

Openfire

= 3.4.3
📦
Igniterealtime

Openfire

= 3.4.4
📦
Igniterealtime

Openfire

= 3.4.5
📦
Igniterealtime

Openfire

= 3.5.0
📦
Igniterealtime

Openfire

= 3.5.1
📦
Igniterealtime

Openfire

= 3.5.2
📦
Igniterealtime

Openfire

= 3.6.0

References & Advisories

相关漏洞威胁