Lucene search

K

Barracudadrive Security Vulnerabilities

cve
cve

CVE-2014-4335

Multiple cross-site scripting (XSS) vulnerabilities in BarracudaDrive 6.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) host or (2) password parameter to...

6AI Score

0.001EPSS

2022-10-03 04:20 PM
19
cve
cve

CVE-2014-3807

Multiple cross-site scripting (XSS) vulnerabilities in BarracudaDrive 6.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) blog, (2) bloggeruser, or (3) bloggerpasswd parameter to...

5.9AI Score

0.002EPSS

2022-10-03 04:20 PM
17
cve
cve

CVE-2020-23834

Insecure Service File Permissions in the bd service in Real Time Logic BarracudaDrive v6.5 allow local attackers to escalate privileges to admin by replacing the %SYSTEMDRIVE%\bd\bd.exe file. When the computer next starts, the new bd.exe will be run as...

8.8CVSS

7.6AI Score

0.001EPSS

2020-09-04 04:15 AM
18
cve
cve

CVE-2014-3808

Multiple cross-site scripting (XSS) vulnerabilities in BarracudaDrive before 6.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) role parameter to roles.lsp, (2) name parameter to user.lsp, (3) path parameter to wizard/setuser.lsp, (4) host parameter to...

5.9AI Score

0.002EPSS

2014-05-21 02:55 PM
21
cve
cve

CVE-2014-2526

Multiple cross-site scripting (XSS) vulnerabilities in BarracudaDrive before 6.7 allow remote attackers to inject arbitrary web script or HTML via the (1) sForumName or (2) sDescription parameter to Forum/manage/ForumManager.lsp; (3) sHint, (4) sWord, or (5) nId parameter to...

6.1CVSS

6AI Score

0.003EPSS

2014-03-25 06:21 PM
21
cve
cve

CVE-2007-6314

BarracudaDrive Web Server before 3.8 allows remote attackers to read the source code for web scripts by appending a (1) + (plus), (2) . (dot), or (3) %80 and similar characters to the file name in the...

6.8AI Score

0.012EPSS

2007-12-12 12:46 AM
14
cve
cve

CVE-2007-6317

Multiple directory traversal vulnerabilities in BarracudaDrive Web Server before 3.8 allow (1) remote attackers to read arbitrary files via certain ..\ (dot dot backslash) sequences in the URL path, or (2) remote authenticated users to delete arbitrary files or create arbitrary directories via a...

6.5AI Score

0.002EPSS

2007-12-12 12:46 AM
16
cve
cve

CVE-2007-6316

Cross-site scripting (XSS) vulnerability in BarracudaDrive Web Server before 3.8 allows remote attackers to inject arbitrary web script or HTML via the URI path in an HTTP GET request, which is activated by administrators viewing log files via the Trace...

5.7AI Score

0.004EPSS

2007-12-12 12:46 AM
16
cve
cve

CVE-2007-6315

Group Chat in BarracudaDrive Web Server before 3.8 allows remote authenticated users to cause a denial of service (crash) via a HTTP request to /eh/chat.ehintf/C. that does not contain a Connection ID, which results in a NULL pointer...

6.2AI Score

0.008EPSS

2007-12-12 12:46 AM
27