Description
img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to execute arbitrary commands via shell metacharacters in the f parameter.
Affected products
- Barracuda Networks / barracuda_spam_firewall3.1.16 – 3.1.16
- Barracuda Networks / barracuda_spam_firewall3.1.17 – 3.1.17
Exploits & proofs of concept
- exploit-dbBarracuda - IMG.pl Remote Command Execution (Metasploit)by Metasploit
- exploit-dbBarracuda Spam Firewall < 3.1.18 - Command Execution (Metasploit)by Nicolas Gregoire
Updated 39m ago · 8 sources