4
CVSSv2

CVE-2006-4000

Published: 05/08/2006 Updated: 17/10/2018
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in cgi-bin/preview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 up to and including 3.3.03.053 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the file parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

barracuda networks barracuda spam firewall 3.3.01.001

barracuda networks barracuda spam firewall 3.3.03.053

barracuda networks barracuda spam firewall 3.3.03.055

Exploits

source: wwwsecurityfocuscom/bid/19276/info Spam Firewall is prone to multiple vulnerabilities, including a directory-traversal issue, access-validation issue, and a remote command-execution issue A remote attacker can exploit these issues to gain access to potentially sensitive information and execute commands in the context of the affe ...