CVE-2006-4000
EXPLOITEDBarracuda Spam Firewall 3.3.01.001-3.3.03.053 Directory Traversal via cgi-bin/preview_email.cgi
Title source: llmExploitation Summary
CVE-2006-4000 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Greg Sinclair.
AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in Spam Firewall, including directory traversal and remote command execution via the `preview_email.cgi` endpoint. It allows an attacker to execute arbitrary commands and access sensitive files without authentication.
Description
Directory traversal vulnerability in cgi-bin/preview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the file parameter.
Exploits (1)
This exploit demonstrates multiple vulnerabilities in Spam Firewall, including directory traversal and remote command execution via the `preview_email.cgi` endpoint. It allows an attacker to execute arbitrary commands and access sensitive files without authentication.