VYPR

Message Archiver

by Barracuda Networks

CVEs (3)

  • CVE-2025-8319MedJul 30, 2025
    risk 0.40cvss 6.1epss 0.00

    the BMA login interface allows arbitrary JavaScript or HTML to be written straight into the page’s Document Object Model via the error= URL parameter

  • CVE-2018-20369MedDec 23, 2018
    risk 0.40cvss 6.1epss 0.01

    Barracuda Message Archiver 2018 has XSS in the error_msg exception-handling value for the ldap_user parameter to the cgi-mod/ldap_load_entry.cgi module. The injection point of the issue is the Add_Update module.

  • CVE-2008-0971Dec 19, 2008
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in Barracuda Spam Firewall (BSF) before 3.5.12.007, Message Archiver before 1.2.1.002, Web Filter before 3.3.0.052, IM Firewall before 3.1.01.017, and Load Balancer before 2.3.024 allow remote attackers to inject…