Directory traversal vulnerability in cgi-bin/preview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the file parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Barracuda_spam_firewall | Barracuda_networks | 3.3.01.001 (including) | 3.3.01.001 (including) |
Barracuda_spam_firewall | Barracuda_networks | 3.3.03.053 (including) | 3.3.03.053 (including) |
Barracuda_spam_firewall | Barracuda_networks | 3.3.03.055 (including) | 3.3.03.055 (including) |