CVE-2008-0971: XSS

Published Dec 19, 2008
·
Updated

Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in Barracuda Spam Firewall (BSF) before 3.5.12.007, Message Archiver before 1.2.1.002, Web Filter before 3.3.0.052, IM Firewall before 3.1.01.017, and Load Balancer before 2.3.024 allow remote attackers to inject arbitrary web script or HTML via (1) the Policy Name field in Search Based Retention Policy in Message Archiver; unspecified parameters in the (2) IP Configuration, (3) Administration, (4) Journal Accounts, (5) Retention Policy, and (6) GroupWise Sync components in Message Archiver; (7) input to search operations in Web Filter; and (8) input used in error messages and (9) hidden INPUT elements in (a) Spam Firewall, (b) IM Firewall, and (c) Web Filter.

Affected Software

5 affected components
Barracuda Networks Barracuda Im Firewall<=3.0.01.008
Barracuda Networks Barracuda Load Balancer<=2.2.006
Barracuda Networks Barracuda Message Archiver<=1.1.0.010
Barracuda Networks Barracuda Spam Firewall<=3.5.11.020
Barracuda Networks Barracuda Web Filter<=3.3.0.038

Event History

Dec 19, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2008-0971?

CVE-2008-0971 is classified as a high severity vulnerability due to its potential for remote code execution via cross-site scripting.

2

How do I fix CVE-2008-0971?

To fix CVE-2008-0971, update your Barracuda Spam Firewall, Web Filter, Load Balancer, Message Archiver, or IM Firewall to the latest patched version.

3

Which Barracuda products are affected by CVE-2008-0971?

CVE-2008-0971 affects Barracuda Spam Firewall versions prior to 3.5.12.007, Message Archiver versions prior to 1.2.1.002, Web Filter versions prior to 3.3.0.052, IM Firewall versions prior to 3.1.01.017, and Load Balancer versions prior to 2.3.024.

4

What types of attacks can CVE-2008-0971 enable?

CVE-2008-0971 can enable remote attackers to inject arbitrary web scripts, potentially leading to data theft or session hijacking.

5

Is there a workaround for CVE-2008-0971 if I cannot update immediately?

As a temporary workaround for CVE-2008-0971, consider implementing additional input validation on user-generated content to mitigate XSS attacks until a full update can be applied.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203