CVE-2007-5058
Summary
| CVE | CVE-2007-5058 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-09-24 22:17:00 UTC |
| Updated | 2018-10-15 21:40:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the Web administration interface in Barracuda Spam Firewall before firmware 3.5.10.016 allows remote attackers to inject arbitrary web script or HTML via the username field in a login attempt, which is not properly handled when the Monitor Web Syslog screen is open. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Barracuda Networks | Barracuda Spam Firewall | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ISR, Infobyte Security Research | MISC | www.infobyte.com.ar | |
| 38156 | OSVDB | osvdb.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Barracuda Spam Firewall Web Administration Console Username HTML Injection Vulnerability | BID | www.securityfocus.com | |
| Barracuda Spam Firewall. Cross-Site Scripting - CXSecurity.com | SREASON | securityreason.com | |
| Barracuda Spam Firewall Input Validation Hole in 'Monitor Web Syslog' Page Permits Cross-Site Scripting Attacks - SecurityTracker | SECTRACK | www.securitytracker.com | |
| Barracuda Spam Firewall "Monitor Web Syslog" Script Insertion - Secunia Advisories - Vulnerability Information - Secunia.com | SECUNIA | secunia.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Error 404 (Not Found) | Barracuda Networks | CONFIRM | www.barracudanetworks.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.