CVE-2008-6511

EUVD-2008-6478
Open redirect vulnerability in login.jsp in Openfire 3.6.0a and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 86%
Affected Products (NVD)
VendorProductVersion
igniterealtimeopenfire
𝑥
≤ 3.6.0a
igniterealtimeopenfire
2.6.0
igniterealtimeopenfire
2.6.1
igniterealtimeopenfire
2.6.2
igniterealtimeopenfire
3.0.0
igniterealtimeopenfire
3.0.1
igniterealtimeopenfire
3.1.0
igniterealtimeopenfire
3.1.1
igniterealtimeopenfire
3.2.0
igniterealtimeopenfire
3.2.1
igniterealtimeopenfire
3.2.2
igniterealtimeopenfire
3.2.3
igniterealtimeopenfire
3.2.4
igniterealtimeopenfire
3.3.0
igniterealtimeopenfire
3.3.2
igniterealtimeopenfire
3.3.3
igniterealtimeopenfire
3.4.0
igniterealtimeopenfire
3.4.1
igniterealtimeopenfire
3.4.3
igniterealtimeopenfire
3.4.4
igniterealtimeopenfire
3.4.5
igniterealtimeopenfire
3.5.0
igniterealtimeopenfire
3.5.1
igniterealtimeopenfire
3.5.2
igniterealtimeopenfire
3.6.0
𝑥
= Vulnerable software versions