Software: OpenFire 3.6.4 Admin Web Console
Severity: Critical (duh! it's the admin!)
History:
5/31/2010 - Discovery
06/01/2010 - Informed support and security @ jivesoftware.com
06/03/2010 - Follow-up email to security@
06/10/2010 - Public release
Details:
It is possible to modify your favorite IM client to execute a script on the Admin's browser:
Most administrators will disable No-Script and RequestPolicy (if they're using FireFox) on internal domains, so this vulnerability makes it very easy to execute a script from a trusted domain.
Mitigation:
Use no-script & request forgery on ALL domains, not just external, or if you're 3r33t0, hack up their code and fix it!
Vendor Response:
Not even a "go screw yourself!"
--thrill
---
It is not the degrees you hold, but the mind you possess. - thrill