CVE-2008-2333
Barracuda Spam Firewall 3.5.11 - 'ldap_test.cgi' Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in ldap_test.cgi in Barracuda Spam Firewall (BSF) before 3.5.11.025 allows remote attackers to inject arbitrary web script or HTML via the email parameter.
Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados enl dap_test.cgi en Barracuda Spam Firewall (BSF) anteriores a 3.5.11.025, permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarias a través del parámetro "email".
The Barracuda Spam Firewall device web administration interface is vulnerable to a reflected cross site scripting vulnerability which may allow theft of administrative credentials or downloading of malicious content. IRM confirmed the presence of this vulnerability in Barracuda Spam Firewall 600 Firmware 3.5.11.020. The vendor has confirmed the issue exists in all versions prior to 3.5.11.025.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-05-18 CVE Reserved
- 2008-05-22 CVE Published
- 2008-05-22 First Exploit
- 2024-08-07 CVE Updated
- 2024-10-25 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/30362 | Third Party Advisory | |
http://www.barracudanetworks.com/ns/support/tech_alert.php | X_refsource_confirm | |
http://www.irmplc.com/index.php/168-Advisory-027 | X_refsource_misc | |
http://www.securityfocus.com/archive/1/492475/100/0/threaded | Mailing List | |
http://www.securitytracker.com/id?1020108 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/1627/references | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/42594 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/31828 | 2008-05-22 |
URL | Date | SRC |
---|---|---|
http://www.securityfocus.com/bid/29340 | 2018-10-11 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Barracuda Networks Search vendor "Barracuda Networks" | Barracuda Spam Firewall Search vendor "Barracuda Networks" for product "Barracuda Spam Firewall" | <= 3.5.11.020 Search vendor "Barracuda Networks" for product "Barracuda Spam Firewall" and version " <= 3.5.11.020" | - |
Affected
| ||||||
Barracuda Networks Search vendor "Barracuda Networks" | Barracuda Spam Firewall Search vendor "Barracuda Networks" for product "Barracuda Spam Firewall" | 3.1.10 Search vendor "Barracuda Networks" for product "Barracuda Spam Firewall" and version "3.1.10" | - |
Affected
| ||||||
Barracuda Networks Search vendor "Barracuda Networks" | Barracuda Spam Firewall Search vendor "Barracuda Networks" for product "Barracuda Spam Firewall" | 3.1.16 Search vendor "Barracuda Networks" for product "Barracuda Spam Firewall" and version "3.1.16" | - |
Affected
| ||||||
Barracuda Networks Search vendor "Barracuda Networks" | Barracuda Spam Firewall Search vendor "Barracuda Networks" for product "Barracuda Spam Firewall" | 3.1.17 Search vendor "Barracuda Networks" for product "Barracuda Spam Firewall" and version "3.1.17" | - |
Affected
| ||||||
Barracuda Networks Search vendor "Barracuda Networks" | Barracuda Spam Firewall Search vendor "Barracuda Networks" for product "Barracuda Spam Firewall" | 3.1.18 Search vendor "Barracuda Networks" for product "Barracuda Spam Firewall" and version "3.1.18" | - |
Affected
| ||||||
Barracuda Networks Search vendor "Barracuda Networks" | Barracuda Spam Firewall Search vendor "Barracuda Networks" for product "Barracuda Spam Firewall" | 3.3.0.54 Search vendor "Barracuda Networks" for product "Barracuda Spam Firewall" and version "3.3.0.54" | - |
Affected
| ||||||
Barracuda Networks Search vendor "Barracuda Networks" | Barracuda Spam Firewall Search vendor "Barracuda Networks" for product "Barracuda Spam Firewall" | 3.3.01.001 Search vendor "Barracuda Networks" for product "Barracuda Spam Firewall" and version "3.3.01.001" | - |
Affected
| ||||||
Barracuda Networks Search vendor "Barracuda Networks" | Barracuda Spam Firewall Search vendor "Barracuda Networks" for product "Barracuda Spam Firewall" | 3.3.3 Search vendor "Barracuda Networks" for product "Barracuda Spam Firewall" and version "3.3.3" | - |
Affected
| ||||||
Barracuda Networks Search vendor "Barracuda Networks" | Barracuda Spam Firewall Search vendor "Barracuda Networks" for product "Barracuda Spam Firewall" | 3.3.03.053 Search vendor "Barracuda Networks" for product "Barracuda Spam Firewall" and version "3.3.03.053" | - |
Affected
| ||||||
Barracuda Networks Search vendor "Barracuda Networks" | Barracuda Spam Firewall Search vendor "Barracuda Networks" for product "Barracuda Spam Firewall" | 3.3.03.055 Search vendor "Barracuda Networks" for product "Barracuda Spam Firewall" and version "3.3.03.055" | - |
Affected
| ||||||
Barracuda Networks Search vendor "Barracuda Networks" | Barracuda Spam Firewall Search vendor "Barracuda Networks" for product "Barracuda Spam Firewall" | 3.3.15.026 Search vendor "Barracuda Networks" for product "Barracuda Spam Firewall" and version "3.3.15.026" | - |
Affected
| ||||||
Barracuda Networks Search vendor "Barracuda Networks" | Barracuda Spam Firewall Search vendor "Barracuda Networks" for product "Barracuda Spam Firewall" | 3.4 Search vendor "Barracuda Networks" for product "Barracuda Spam Firewall" and version "3.4" | - |
Affected
| ||||||
Barracuda Networks Search vendor "Barracuda Networks" | Barracuda Spam Firewall Search vendor "Barracuda Networks" for product "Barracuda Spam Firewall" | 3.4.10.102 Search vendor "Barracuda Networks" for product "Barracuda Spam Firewall" and version "3.4.10.102" | - |
Affected
|