CVE-2008-1094: SQL Injection
Published Dec 19, 2008
·Updated
SQL injection vulnerability in index.cgi in the Account View page in Barracuda Spam Firewall (BSF) before 3.5.12.007 allows remote authenticated administrators to execute arbitrary SQL commands via a patternx parameter in a searchcountequals action, as demonstrated by the pattern0 parameter.
Affected Software
1 affected component
Barracuda Networks Barracuda Spam Firewall<=3.5.11.020
Event History
Dec 19, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1094?
CVE-2008-1094 has a medium severity rating due to its potential impact on database integrity.
2
How do I fix CVE-2008-1094?
To fix CVE-2008-1094, upgrade Barracuda Spam Firewall to version 3.5.12.007 or later.
3
Who is affected by CVE-2008-1094?
CVE-2008-1094 affects Barracuda Spam Firewall versions prior to 3.5.12.007.
4
What type of vulnerability is CVE-2008-1094?
CVE-2008-1094 is classified as an SQL injection vulnerability.
5
Can CVE-2008-1094 be exploited remotely?
Yes, CVE-2008-1094 can be exploited remotely by authenticated administrators.