4.3
CVSSv2

CVE-2008-2333

Published: 23/05/2008 Updated: 11/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in ldap_test.cgi in Barracuda Spam Firewall (BSF) prior to 3.5.11.025 allows remote malicious users to inject arbitrary web script or HTML via the email parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

barracuda networks barracuda spam firewall 3.1.10

barracuda networks barracuda spam firewall 3.3.03.055

barracuda networks barracuda spam firewall 3.3.15.026

barracuda networks barracuda spam firewall 3.1.18

barracuda networks barracuda spam firewall 3.3.0.54

barracuda networks barracuda spam firewall 3.4.10.102

barracuda networks barracuda spam firewall

barracuda networks barracuda spam firewall 3.1.16

barracuda networks barracuda spam firewall 3.1.17

barracuda networks barracuda spam firewall 3.3.3

barracuda networks barracuda spam firewall 3.4

barracuda networks barracuda spam firewall 3.3.01.001

barracuda networks barracuda spam firewall 3.3.03.053

Exploits

source: wwwsecurityfocuscom/bid/29340/info Barracuda Spam Firewall is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site This m ...
The Barracuda Spam Firewall device web administration interface is vulnerable to a reflected cross site scripting vulnerability which may allow theft of administrative credentials or downloading of malicious content IRM confirmed the presence of this vulnerability in Barracuda Spam Firewall 600 Firmware 3511020 The vendor has confirmed the iss ...