Barracuda Spam Firewall Input Validation Hole in 'Monitor Web Syslog' Page Permits Cross-Site Scripting Attacks
|
|
SecurityTracker Alert ID: 1018733
|
|
SecurityTracker URL: http://securitytracker.com/id?1018733
|
|
CVE Reference: CVE-2007-5058
(Links to External Site)
|
Updated: Mar 20 2008
|
Original Entry Date: Sep 24 2007
|
Impact: Disclosure of authentication information, Disclosure of user information, Execution of arbitrary code via network, Modification of user information
|
Fix Available: Yes
Exploit Included: Yes
Vendor Confirmed: Yes
|
Version(s): 3.5.10.013 and prior versions
|
Description: A vulnerability was reported in Barracuda Spam Firewall. A remote user can conduct cross-site scripting attacks.
The web administration console does not properly filter HTML code from user-supplied input in the 'username' parameter before displaying
the input when the 'Monitor Web Syslog' page is displayed. A remote user can cause arbitrary scripting code to be executed by the
target user's browser. The code will originate from the Barracuda Spam Firewall device and will run in the security context of
that device. As a result, the code will be able to access the target user's cookies (including authentication cookies), if any,
associated with the device, access data recently submitted by the target user via web form to the device, or take actions on the
device acting as the target user.
A demonstration exploit value is provided:
john@<script>alert("String")</script>.blah.com
The
vendor was notified on August 24, 2007.
The original advisory is available at:
http://www.infobyte.com.ar/adv/ISR-15.html
Federico
Kirschbaum of Infobyte Security Research reported this vulnerability.
|
Impact: A remote user can access the target user's cookies (including authentication cookies), if any, associated with the Barracuda Spam
Firewall device, access data recently submitted by the target user via web form to the device, or take actions on the device acting
as the target user.
|
Solution: The vendor has issued a fixed version (3.5.10.10.016).
The vendor's advisory is available at:
http://www.barracudanetworks.com/ns/support/tech_alert.php
|
Vendor URL: www.barracudanetworks.com/ns/support/tech_alert.php (Links to External Site)
|
Cause: Input validation error
|
|
Message History:
None.
|
Source Message Contents
|
Date: Mon, 24 Sep 2007 17:12:59 -0400
Subject: Barracuda Spam Firewall Cross-Site Scripting
|
http://www.infobyte.com.ar/adv/ISR-15.html
|
|