vendor:
Control Center Application
by:
Vulnerability-lab Team
6.5
CVSS
MEDIUM
Multiple persistent and non-persistent Input Validation vulnerabilities
20, 79
CWE
Product Name: Control Center Application
Affected Version From: 620
Affected Version To: 620
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2011
Barracuda Control Center 620 – Multiple Web Vulnerabilities
Multiple persistent and non-persistent Input Validation vulnerabilities are detected on Barracudas Control Center 620. Local low privileged user account can implement/inject malicious persistent script code. When exploited by an authenticated user, the identified vulnerabilities can lead to information disclosure, access to intranet available servers, manipulated persistent content. Attackers can form malicious client-side requests to hijack customer/admin sessions. Successful exploitation requires user interaction and can lead to information disclosure, session hijacking and access to servers in the intranet.
Mitigation:
Ensure that user input is properly validated and sanitized before being used in the application.