CVE-2014-2526
6.1 · MEDIUMOverview
CVE-2014-2526 is a medium-severity vulnerability affecting barracudadrive barracudadrive. It was published on March 25, 2014 and has a CVSS 3.1 base score of 6.1 (MEDIUM).
This vulnerability has a CVSS 3.1 base score of 6.1, rated MEDIUM. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.
Technical Description
Multiple cross-site scripting (XSS) vulnerabilities in BarracudaDrive before 6.7 allow remote attackers to inject arbitrary web script or HTML via the (1) sForumName or (2) sDescription parameter to Forum/manage/ForumManager.lsp; (3) sHint, (4) sWord, or (5) nId parameter to Forum/manage/hangman.lsp; (6) user parameter to rtl/protected/admin/wizard/setuser.lsp; (7) name or (8) email parameter to feedback.lsp; (9) lname or (10) url parameter to private/manage/PageManager.lsp; (11) cmd parameter to fs; (12) newname, (13) description, (14) firstname, (15) lastname, or (16) id parameter to rtl/protected/mail/manage/list.lsp; or (17) PATH_INFO to fs/.
Remediation
Check the references section for vendor advisories and patches from barracudadrive. Update barracudadrive to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.
Affected Products
| Vendor | Product | Versions | Status |
|---|---|---|---|
| barracudadrive | barracudadrive | >= 0, < 6.7 | Affected |
References
Frequently Asked Questions
What is CVE-2014-2526?
CVE-2014-2526 is a medium-severity vulnerability affecting barracudadrive barracudadrive. It was published on March 25, 2014 and has a CVSS 3.1 base score of 6.1 (MEDIUM).
How severe is CVE-2014-2526?
This vulnerability has a CVSS 3.1 base score of 6.1, rated MEDIUM. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.
How do I fix or remediate CVE-2014-2526?
Check the references section for vendor advisories and patches from barracudadrive. Update barracudadrive to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.
How can CyberStrike help with CVE-2014-2526?
CyberStrike's AI-powered security agents can automatically detect CVE-2014-2526 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.
How CyberStrike Helps
AI agents map your attack surface to find vulnerabilities like this one.
Automated penetration testing that runs continuously, not just quarterly.
AI-driven PR review catches vulnerable dependencies before they ship.
Browser-based exploitation validates findings with real proof-of-concept.
Related MEDIUM CVEs from 2014
View all →Sophos Disk Encryption (SDE) 5.x in Sophos Enterprise Console (SEC) 5.x before 5.2.2 does not enforc
The png_do_expand_palette function in libpng before 1.6.8 allows remote attackers to cause a denial
A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerabilit
The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to
The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote
Heap-based buffer overflow in the read_u32 function in Mozilla Firefox before 29.0, Firefox ESR 24.x
Integer overflow in the png_set_unknown_chunks function in libpng/pngset.c in libpng before 1.5.14be
Multiple integer overflows in libpng before 1.5.14rc03 allow remote attackers to cause a denial of s
IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file
The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component i
Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo
The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP