Vulnerability record · CVE-2005-2847 · published 8 September 2005
CVE-2005-2847: Barracuda Spam Firewall img.pl command injection via f parameter
Barracuda Networks · Barracuda Spam Firewall
The img.pl script in Barracuda Spam Firewall firmware 3.1.16 and 3.1.17 passes the f parameter to a shell without sanitizing shell metacharacters, allowing command injection. Because the endpoint is network-reachable and requires no authentication, this is a serious pre-auth remote code execution flaw on a perimeter security appliance.
Description
img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to execute arbitrary commands via shell metacharacters in the f parameter.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
critical priorityUnauthenticated remote command execution on an internet-facing security appliance with public exploit code and very high EPSS probability.
What it is
The img.pl script in Barracuda Spam Firewall firmware 3.1.16 and 3.1.17 passes the f parameter to a shell without sanitizing shell metacharacters, allowing command injection. Because the endpoint is network-reachable and requires no authentication, this is a serious pre-auth remote code execution flaw on a perimeter security appliance.
Impact
An unauthenticated remote attacker can execute arbitrary commands on the appliance, gaining control of the device and potentially pivoting into the internal network it protects.
Attack surface
Reached over the network via HTTP requests to img.pl with crafted shell metacharacters in the f parameter; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.53375 (99th percentile) and multiple references are tagged Exploit, indicating public exploit code exists and exploitation is likely.
What to do
- Apply the vendor patch referenced in the Secunia and SecurityFocus advisories; upgrade firmware beyond 3.1.16/3.1.17.
- If patching is not immediately possible, restrict network access to the appliance management/web interface to trusted administrative hosts only.
- Place the appliance behind a filtering reverse proxy or WAF rule that blocks shell metacharacters in requests to img.pl.
- Monitor and audit the appliance for signs of compromise and rotate any credentials stored on it.
Detection
- Inspect HTTP request logs for img.pl requests containing shell metacharacters (;, |, `, $(), &&) in the f parameter.
- Monitor for unexpected child processes or shell execution spawned by the web server process on the appliance.
- Alert on outbound connections from the appliance to unusual destinations that could indicate command-and-control or data exfiltration.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://marc.info/?l=bugtraq&m=112560044813390&w=2 | |
| http://secunia.com/advisories/16683/ | PatchVendor Advisory |
| http://www.securityfocus.com/bid/14712 | ExploitPatch |
| http://www.securitytracker.com/alerts/2005/Sep/1014837.html | ExploitPatchVendor Advisory |
| http://www.securiweb.net/wiki/Ressources/AvisDeSecurite/2005.1 | ExploitPatchVendor Advisory |
| http://marc.info/?l=bugtraq&m=112560044813390&w=2 | |
| http://secunia.com/advisories/16683/ | PatchVendor Advisory |
| http://www.securityfocus.com/bid/14712 | ExploitPatch |
| http://www.securitytracker.com/alerts/2005/Sep/1014837.html | ExploitPatchVendor Advisory |
| http://www.securiweb.net/wiki/Ressources/AvisDeSecurite/2005.1 | ExploitPatchVendor Advisory |
Track CVE-2005-2847 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-2847), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.