Barracuda SSL VPN Unspecified Cross Site Scripting Vulnerability
23 Jul. 2012
Summary
Barracuda SSL VPN is prone to an unspecified cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
Credit:
The original article can be found at: http://www.securityfocus.com/bid/54593 .
The information has been provided by Benjamin Kunz Mejri of Vulnerability Research Laboratory .
Vulnerable Systems:
*Barracuda SSL VPN Unspecified Cross Site Scripting Vulnerability
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Versions prior to Barracuda SSL VPN 2.2.2.23 are vulnerable.
Vendor Status:
Currently we are not aware of any vendor-supplied patches