PT-2007-6161 · Barracuda · Barracuda Spam Firewall

Publicado

2007-09-24

·

Atualizado

2018-10-15

·

CVE-2007-5058

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Barracuda Spam Firewall versions prior to 3.5.10.016
Description The issue is related to a cross-site scripting (XSS) vulnerability in the Web administration interface. This vulnerability allows remote attackers to inject arbitrary web script or HTML via the username field in a login attempt. The vulnerability is triggered when the Monitor Web Syslog screen is open and the input is not properly handled.
Recommendations For versions prior to 3.5.10.016, update to firmware version 3.5.10.016 or later to resolve the issue. As a temporary workaround, consider restricting access to the Web administration interface and avoiding the use of the username field in login attempts when the Monitor Web Syslog screen is open.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-5058

Produtos afetados

Barracuda Spam Firewall