CVE-2014-3808
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in BarracudaDrive before 6.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) role parameter to roles.lsp, (2) name parameter to user.lsp, (3) path parameter to wizard/setuser.lsp, (4) host parameter to tunnelconstr.lsp, or (5) newpath parameter to wfsconstr.lsp in rtl/protected/admin/.
Múltiples vulnerabilidades de XSS en BarracudaDrive anterior a 6.7.2 permiten a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través del (1) parámetro role hacia roles.lsp, (2) parámetro name hacia user.lsp, (3) parámetro path hacia wizard/setuser.lsp, (4) parámetro host hacia tunnelconstr.lsp o (5) parámetro newpath hacia wfsconstr.lsp en rtl/protected/admin/.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-05-21 CVE Reserved
- 2014-05-21 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://secpod.org/blog/?p=2309 | X_refsource_misc | |
http://secunia.com/advisories/58309 | Third Party Advisory | |
http://www.securityfocus.com/bid/67138 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://secpod.org/advisories/SecPod_Advistory_BarracudaDrive_6.7.1_Mult_XSS_Vuln.txt | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Barracudadrive Search vendor "Barracudadrive" | Barracudadrive Search vendor "Barracudadrive" for product "Barracudadrive" | <= 6.7.1 Search vendor "Barracudadrive" for product "Barracudadrive" and version " <= 6.7.1" | - |
Affected
| ||||||
Barracudadrive Search vendor "Barracudadrive" | Barracudadrive Search vendor "Barracudadrive" for product "Barracudadrive" | 6.0 Search vendor "Barracudadrive" for product "Barracudadrive" and version "6.0" | - |
Affected
| ||||||
Barracudadrive Search vendor "Barracudadrive" | Barracudadrive Search vendor "Barracudadrive" for product "Barracudadrive" | 6.1 Search vendor "Barracudadrive" for product "Barracudadrive" and version "6.1" | - |
Affected
| ||||||
Barracudadrive Search vendor "Barracudadrive" | Barracudadrive Search vendor "Barracudadrive" for product "Barracudadrive" | 6.2 Search vendor "Barracudadrive" for product "Barracudadrive" and version "6.2" | - |
Affected
| ||||||
Barracudadrive Search vendor "Barracudadrive" | Barracudadrive Search vendor "Barracudadrive" for product "Barracudadrive" | 6.3 Search vendor "Barracudadrive" for product "Barracudadrive" and version "6.3" | - |
Affected
| ||||||
Barracudadrive Search vendor "Barracudadrive" | Barracudadrive Search vendor "Barracudadrive" for product "Barracudadrive" | 6.4 Search vendor "Barracudadrive" for product "Barracudadrive" and version "6.4" | - |
Affected
| ||||||
Barracudadrive Search vendor "Barracudadrive" | Barracudadrive Search vendor "Barracudadrive" for product "Barracudadrive" | 6.6 Search vendor "Barracudadrive" for product "Barracudadrive" and version "6.6" | - |
Affected
| ||||||
Barracudadrive Search vendor "Barracudadrive" | Barracudadrive Search vendor "Barracudadrive" for product "Barracudadrive" | 6.7 Search vendor "Barracudadrive" for product "Barracudadrive" and version "6.7" | - |
Affected
| ||||||
Realtimelogic Search vendor "Realtimelogic" | Barracudadrive Search vendor "Realtimelogic" for product "Barracudadrive" | 6.5 Search vendor "Realtimelogic" for product "Barracudadrive" and version "6.5" | - |
Affected
|