First published: Mon Sep 24 2007(Updated: )
Cross-site scripting (XSS) vulnerability in the Web administration interface in Barracuda Spam Firewall before firmware 3.5.10.016 allows remote attackers to inject arbitrary web script or HTML via the username field in a login attempt, which is not properly handled when the Monitor Web Syslog screen is open.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Barracuda Spam Firewall | <=3.4.10.102 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5058 has a medium severity level primarily due to the potential impact of cross-site scripting attacks.
To mitigate CVE-2007-5058, upgrade the Barracuda Spam Firewall to firmware version 3.5.10.016 or later.
CVE-2007-5058 is caused by insufficient validation of input data in the username field on the Barracuda Spam Firewall's web administration interface.
Users of Barracuda Spam Firewall versions prior to 3.5.10.016 are affected by CVE-2007-5058.
CVE-2007-5058 is classified as a cross-site scripting (XSS) vulnerability.