vendor:
Barracuda SSL VPN 680Vx
by:
Gjoko 'LiquidWorm' Krstic
8,8
CVSS
HIGH
Stored XSS
79
CWE
Product Name: Barracuda SSL VPN 680Vx
Affected Version From: 2.3.3.193
Affected Version To: 2.3.3.216
Patch Exists: YES
Related CWE: N/A
CPE: h:barracuda:ssl_vpn_680vx
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux 2.4.x, Jetty Web Server
2013
Barracuda SSL VPN 680Vx 2.3.3.193 Multiple Script Injection Vulnerabilities
Barracuda SSL VPN suffers from multiple stored XSS vulnerabilities when parsing user input to several parameters via POST method. Attackers can exploit these weaknesses to execute arbitrary HTML and script code in a user's browser session.
Mitigation:
Upgrade to the latest version of Barracuda SSL VPN (2.3.3.216) to mitigate this vulnerability.