CVE-2008-1094
SQL injection vulnerability in index.cgi in the Account View page in Barracuda Spam Firewall (BSF) before 3.5.12.007 allows remote authenticated administrators to execute arbitrary SQL commands via a pattern_x parameter in a search_count_equals action,…
Does this matter?
Lower severity and a low EPSS score (1.98%). Track it; it rarely justifies an emergency change on its own.
Description
SQL injection vulnerability in index.cgi in the Account View page in Barracuda Spam Firewall (BSF) before 3.5.12.007 allows remote authenticated administrators to execute arbitrary SQL commands via a pattern_x parameter in a search_count_equals action, as demonstrated by the pattern_0 parameter.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.98% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- barracuda networks/barracuda spam firewall
- Source
- cve@mitre.org
References
- http://dcsl.ul.ie/advisories/02.htmExploit
- http://secunia.com/advisories/33164Vendor Advisory
- http://securityreason.com/securityalert/4793
- http://securitytracker.com/id?1021455
- http://www.barracudanetworks.com/ns/support/tech_alert.phpVendor Advisory
- http://www.securityfocus.com/archive/1/499293/100/0/threaded
- https://www.exploit-db.com/exploits/7496
- http://dcsl.ul.ie/advisories/02.htmExploit
- http://secunia.com/advisories/33164Vendor Advisory
- http://securityreason.com/securityalert/4793
- http://securitytracker.com/id?1021455
- http://www.barracudanetworks.com/ns/support/tech_alert.phpVendor Advisory
- http://www.securityfocus.com/archive/1/499293/100/0/threaded
- https://www.exploit-db.com/exploits/7496
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.