← Vulnerability feed

Vulnerability record · CVE-2008-1094 · published 19 December 2008

CVE-2008-1094: Barracuda networks barracuda spam firewall sql injection vulnerability

Barracuda Networks · Barracuda Spam Firewall

SQL injection vulnerability in index.cgi in the Account View page in Barracuda Spam Firewall (BSF) before 3.5.12.007 allows remote authenticated administrators to execute arbitrary SQL commands via a pattern_x parameter in a search_count_equals action, as demonstrated by the pattern_0 parameter.

6.5 CVSS 2.0 Medium EPSS 2.0% · top 20.3% CWE-89 · SQL injection
6.5CVSS 2.0 base score
2.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

SQL injection vulnerability in index.cgi in the Account View page in Barracuda Spam Firewall (BSF) before 3.5.12.007 allows remote authenticated administrators to execute arbitrary SQL commands via a pattern_x parameter in a search_count_equals action, as demonstrated by the pattern_0 parameter.

AV:N/AC:L/Au:S/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-1094 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2007-1673Amavis vulnerabilityunzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a …EPSS 3.2%7.5CVE-2006-4081Barracuda networks barracuda spam firewall vulnerabilitypreview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 allows remote attackers to execute commands via shell metacharacters…EPSS 4.3%7.5CVE-2006-4001Barracuda networks barracuda spam firewall vulnerabilityLogin.pm in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 contains a hard-coded password for the guest account, which allows remote att…EPSS 1.9%7.5CVE-2005-2847Barracuda Spam Firewall img.pl command injection via f parameterThe img.pl script in Barracuda Spam Firewall firmware 3.1.16 and 3.1.17 passes the f parameter to a shell without sanitizing shell metacharacters, al…EPSS 53%analysed7.5CVE-2005-0431Barracuda networks barracuda spam firewall vulnerabilityBarracuda Spam Firewall 3.1.10 and earlier does not restrict the domains that white-listed domains can send mail to, which allows members of white-li…EPSS 1.3%7.2CVE-2006-4082Barracuda networks barracuda spam firewall vulnerabilityBarracuda Spam Firewall (BSF), possibly 3.3.03.053, contains a hardcoded password for the admin account for logins from 127.0.0.1 (localhost), which …EPSS 0.37%6.4CVE-2005-2849Barracuda networks barracuda spam firewall vulnerabilityArgument injection vulnerability in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to (1) read portions of source…EPSS 1.4%5.0CVE-2005-2848Barracuda networks barracuda spam firewall vulnerabilityDirectory traversal vulnerability in img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to read arbitrary f…EPSS 8.8%

Source: NIST National Vulnerability Database (record CVE-2008-1094), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.