3.5
CVSSv2

CVE-2008-0971

Published: 19/12/2008 Updated: 15/10/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in Barracuda Spam Firewall (BSF) prior to 3.5.12.007, Message Archiver prior to 1.2.1.002, Web Filter prior to 3.3.0.052, IM Firewall prior to 3.1.01.017, and Load Balancer prior to 2.3.024 allow remote malicious users to inject arbitrary web script or HTML via (1) the Policy Name field in Search Based Retention Policy in Message Archiver; unspecified parameters in the (2) IP Configuration, (3) Administration, (4) Journal Accounts, (5) Retention Policy, and (6) GroupWise Sync components in Message Archiver; (7) input to search operations in Web Filter; and (8) input used in error messages and (9) hidden INPUT elements in (a) Spam Firewall, (b) IM Firewall, and (c) Web Filter.

Vulnerable Product Search on Vulmon Subscribe to Product

barracuda networks barracuda spam firewall

barracuda networks barracuda im firewall

barracuda networks barracuda load balancer

barracuda networks barracuda message archiver

barracuda networks barracuda web filter

Exploits

The Barracuda Networks Message Archiver product is vulnerable to persistent and reflect cross site scripting attacks ...

Github Repositories

OWASP-Top-10-practice This repository used for save results of learning Web Application Security on practice It contains files by categories OWASP TOP10 2013 At the beginning those files were with vulnerable code After some tests, vulnerabilities were patched If you want, you may use this files to your experiments It is very easy to make files vulnerable again Links, that