CVE
- Id
- 31211
- CVE No.
- CVE-2008-1094
- Status
- Candidate
- Description
- SQL injection vulnerability in index.cgi in the Account View page in Barracuda Spam Firewall (BSF) before 3.5.12.007 allows remote authenticated administrators to execute arbitrary SQL commands via a pattern_x parameter in a search_count_equals action, as demonstrated by the pattern_0 parameter.
- Phase
- Assigned (20080228)
- Votes
- None (candidate not yet proposed)
- Comments