Barracuda Networks Spam Firewall Cross-Site Scripting Vulnerability

Barracuda Networks Spam Firewall Cross-Site Scripting Vulnerability (CVE Number: CVE-2008-2333)

Vulnerability Type / Importance: Cross-Site Scripting (Reflected) / Medium

Problem Discovered: 24 April 2008
Vendor Contacted: 24 April 2008
Advisory Published: 22 May 2008

Abstract
The Barracuda Spam Firewall device web administration interface is vulnerable to a reflected cross-site scripting vulnerability which may allow theft of administrative credentials or downloading of malicious content.

Description
The Barracuda device presents LDAP testing functionality via a script called ‘ldap_test.cgi'. The script does not sufficiently validate user-supplied input within the ‘email' parameter. As a result, client-supplied script code can be injected into the ‘email' parameter that would execute in the browser within the security context of the Barracuda device.

Vendor information: http://www.barracudanetworks.com/ns/support/tech_alert.php

Proof of Concept
https://<vulnerablehost>/cgi-bin/ldap_test.cgi?host=127.0.0.1&port=1&tls_mode=tls_mode&tls_require=&username=&password=&filter=&searchbase=&unique_attr=&email_attr=&domain=*&email=%3Cscript%3Ealert(document.cookie)%3C/script%3E


Mitigation
Access to the web management application can be limited by IP address. Firmware release 3.5.11.025 has been released by the vendor to address this issue; however the patch has not been tested by IRM.

Tested/Affected Versions
IRM confirmed the presence of this vulnerability in Barracuda Spam Firewall 600 Firmware 3.5.11.020.
The vendor has confirmed the issue exists in all versions prior to 3.5.11.025.

Credits
Research and Advisory: Information Risk Management Plc.

Disclaimer
All information in this advisory is provided on an 'as is' basis in the hope that it will be useful. Information Risk Management Plc is not responsible for any risks or occurrences caused by the application of this information.