CVE-2009-0496 | Ignite Realtime Openfire 3.6.2 logviewer.jsp propName cross site scripting (EDB-32677 / Nessus ID 35458)
A vulnerability, which was classified as problematic, was found in Ignite Realtime Openfire 3.6.2. Affected is an unknown function of the file logviewer.jsp. The manipulation of the argument propName leads to cross site scripting.
This vulnerability is traded as CVE-2009-0496. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.