Summary
The Barracuda Web Application Firewall 660 is prone to multiple HTML- injection vulnerabilities.
Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie- based authentication credentials or to control how the site is rendered to the user
other attacks are also possible.
The Barracuda Web Application Firewall 660 firmware 7.3.1.007 is vulnerable
other versions may also be affected.
References
Severity
Classification
-
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N
Related Vulnerabilities
- Apache Web Server ETag Header Information Disclosure Weakness
- Apache Tomcat cal2.jsp Cross Site Scripting Vulnerability
- Apache ActiveMQ 'admin/queueBrowse' Cross Site Scripting Vulnerability
- AeroMail Cross Site Request Forgery, HTML Injection and Cross Site Scripting Vulnerabilities
- aeNovo Database Content Disclosure Vulnerability