Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-6317. PoCs published by Luigi Auriemma.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in BarracudaDrive Web Server, including directory traversal, script source visualization, arbitrary file deletion, NULL pointer crash, and HTML injection. It provides clear examples of HTTP requests to exploit these flaws.
Description
Multiple directory traversal vulnerabilities in BarracudaDrive Web Server before 3.8 allow (1) remote attackers to read arbitrary files via certain ..\ (dot dot backslash) sequences in the URL path, or (2) remote authenticated users to delete arbitrary files or create arbitrary directories via a ..\ (dot dot backslash) sequence in the dir parameter to /drive/c/bdusers/USER/.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in BarracudaDrive Web Server, including directory traversal, script source visualization, arbitrary file deletion, NULL pointer crash, and HTML injection. It provides clear examples of HTTP requests to exploit these flaws.