CVE-2005-2848
45Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actepss 8.8%
from disclosure to weapon19 days
Published on NVDSep 8
1st PoC+19d
VulnCheck+5563d
exploitation probability
8.8%top 5% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
Directory traversal vulnerability in img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/1236⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://marc.info/?l=bugtraq&m=112560044813390&w=2http://secunia.com/advisories/16683/http://securiweb.net/wiki/Ressources/AvisDeSecurite/2005.1https://exchange.xforce.ibmcloud.com/vulnerabilities/22120http://www.securityfocus.com/bid/14710http://www.securitytracker.com/alerts/2005/Sep/1014837.html