Unrated severityNVD Advisory· Published Mar 23, 2009· Updated Jun 16, 2026
CVE-2008-6510
CVE-2008-6510
Description
Cross-site scripting (XSS) vulnerability in login.jsp in the Admin Console in Openfire 3.6.0a and earlier allows remote attackers to inject arbitrary web script or HTML via the url parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
26cpe:2.3:a:igniterealtime:openfire:*:*:*:*:*:*:*:*+ 24 more
- cpe:2.3:a:igniterealtime:openfire:*:*:*:*:*:*:*:*range: <=3.6.0a
- cpe:2.3:a:igniterealtime:openfire:2.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:igniterealtime:openfire:2.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:igniterealtime:openfire:2.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:igniterealtime:openfire:3.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:igniterealtime:openfire:3.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:igniterealtime:openfire:3.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:igniterealtime:openfire:3.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:igniterealtime:openfire:3.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:igniterealtime:openfire:3.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:igniterealtime:openfire:3.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:igniterealtime:openfire:3.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:igniterealtime:openfire:3.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:igniterealtime:openfire:3.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:igniterealtime:openfire:3.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:igniterealtime:openfire:3.3.3:*:*:*:*:*:*:*
- cpe:2.3:a:igniterealtime:openfire:3.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:igniterealtime:openfire:3.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:igniterealtime:openfire:3.4.3:*:*:*:*:*:*:*
- cpe:2.3:a:igniterealtime:openfire:3.4.4:*:*:*:*:*:*:*
- cpe:2.3:a:igniterealtime:openfire:3.4.5:*:*:*:*:*:*:*
- cpe:2.3:a:igniterealtime:openfire:3.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:igniterealtime:openfire:3.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:igniterealtime:openfire:3.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:igniterealtime:openfire:3.6.0:*:*:*:*:*:*:*
- Range: <=3.6.0a
Patches
Vulnerability mechanics
References
7- www.andreas-kurtz.de/advisories/AKADV2008-001-v1.0.txtnvdExploit
- www.securityfocus.com/bid/32189nvdExploit
- www.vupen.com/english/advisories/2008/3061nvdVendor Advisory
- www.igniterealtime.org/issues/browse/JM-629nvd
- www.securityfocus.com/archive/1/498162/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/46486nvd
- www.exploit-db.com/exploits/7075nvd
News mentions
0No linked articles in our index yet.