Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2006-4000

EPSS 4.01% · P89
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2006-4000

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Directory traversal vulnerability in cgi-bin/preview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the file parameter.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Barracuda Networks垃圾邮件防火墙安全泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Barracuda Spam Firewall是用于保护邮件服务器的集成硬件和软件垃圾邮件解决方案。 Barracuda垃圾邮件防火墙Login.pm脚本中的guest帐号有硬编码的口令bnadmin99。尽管guest帐号仅有有限的访问能力,但还是可以获取以下信息: * 系统配置,包括IP地址、管理员IP ACL; * 邮件消息日志(但没有消息的内容); * 垃圾邮件/杀毒定义的版本信息和系统固件版本。 Barracuda的preview_email.cgi脚本中还存在文件泄露漏洞。这个脚本用于从Bar
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2006-4000

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2006-4000

Please Login to view more intelligence information

Same Patch Batch · n/a · 2006-08-05 · 31 CVEs total

CVE-2006-3982Knusperleicht Quickie 'quickie.php' Quick_Path参数远程文件包含漏洞
CVE-2006-3996Atutor 'index.php'多个SQL注入漏洞
CVE-2006-3995Mambo或Joomla软件 User Home Pages 'UHP_CONFIG.PHP'远程文件包含漏洞
CVE-2006-3994XMB Forum U2UID 'u2u.inc.php' SQL注入漏洞
CVE-2006-3993The Search Engine Project (TSEP) 'colorswitch.php'远程文件包含漏洞
CVE-2006-3992Intel PRO/Wireless网络连接驱动远程代码执行漏洞
CVE-2006-3991Voodoo Chat 'index.php' File_Path参数远程文件包含漏洞
CVE-2006-3990Paul M. Jones Savant2 多个PHP远程文件包含漏洞
CVE-2006-3989Knusperleicht ShoutBox SB_INCLUDE_PATH参数远程文件包含漏洞
CVE-2006-3988Knusperleicht NewsReporter 'index.php' News_include_path远程文件包含漏洞
CVE-2006-3987Knusperleicht FileManager 'index.php' PHP远程文件包含漏洞
CVE-2006-3986Knusperleicht NewsLetter 'Index.PHP' 远程文件包含漏洞
CVE-2006-3985ConeXware PowerArchiver 'DZIPS32.DLL文件'栈缓冲区溢出漏洞
CVE-2006-3984PHPAuction 'view.inc.php' PHPAds_Path变量远程文件包含漏洞
CVE-2006-3983PHPReactor 'EditProfile.PHP'远程文件包含漏洞
CVE-2005-0985Mac OS X 未明漏洞
CVE-2006-3981Mambo Mambo Gallery Manager 'about.mgm.php'PHP远程文件包含漏洞
CVE-2006-3980Mambo Gallery Manager 'help.mgm.php' MosConfig_Absolute_Path远程文件包含漏洞
CVE-2006-3457Symantec On-Demand Agent(SODA)和Symantec On-Demand Protection(SODP)加密数据信息泄露漏洞
CVE-2006-4001Barracuda Spam Firewall垃圾邮件防火墙 'preview_email.cg' 脚本未明安全漏洞

Showing top 20 of 31 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2006-4000

No comments yet


Leave a comment