Loading vulnerability details…
CVSS v3.1
N/A
EPSS
83.38%
Published
Mar 23, 2009
Modified
Apr 22, 2026
Public PoC / Exploit (3)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Directory traversal vulnerability in the AuthCheck filter in the Admin Console in Openfire 3.6.0a and earlier allows remote attackers to bypass authentication and access the admin interface via a .. (dot dot) in a URI that matches the Exclude-Strings list, as demonstrated by a /setup/setup-/.. sequence in a URI.
Weaknesses (CWE)
Affected Products (25)
References (20)