← Vulnerability feed

Vulnerability record · CVE-2005-2847 · published 8 September 2005

CVE-2005-2847: Barracuda Spam Firewall img.pl command injection via f parameter

Barracuda Networks · Barracuda Spam Firewall

The img.pl script in Barracuda Spam Firewall firmware 3.1.16 and 3.1.17 passes the f parameter to a shell without sanitizing shell metacharacters, allowing command injection. Because the endpoint is network-reachable and requires no authentication, this is a serious pre-auth remote code execution flaw on a perimeter security appliance.

7.5 CVSS 2.0 High EPSS 53% · top 1.0%
7.5CVSS 2.0 base score
53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to execute arbitrary commands via shell metacharacters in the f parameter.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityUnauthenticated remote command execution on an internet-facing security appliance with public exploit code and very high EPSS probability.

What it is

The img.pl script in Barracuda Spam Firewall firmware 3.1.16 and 3.1.17 passes the f parameter to a shell without sanitizing shell metacharacters, allowing command injection. Because the endpoint is network-reachable and requires no authentication, this is a serious pre-auth remote code execution flaw on a perimeter security appliance.

Impact

An unauthenticated remote attacker can execute arbitrary commands on the appliance, gaining control of the device and potentially pivoting into the internal network it protects.

Attack surface

Reached over the network via HTTP requests to img.pl with crafted shell metacharacters in the f parameter; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV, but EPSS is 0.53375 (99th percentile) and multiple references are tagged Exploit, indicating public exploit code exists and exploitation is likely.

What to do

  • Apply the vendor patch referenced in the Secunia and SecurityFocus advisories; upgrade firmware beyond 3.1.16/3.1.17.
  • If patching is not immediately possible, restrict network access to the appliance management/web interface to trusted administrative hosts only.
  • Place the appliance behind a filtering reverse proxy or WAF rule that blocks shell metacharacters in requests to img.pl.
  • Monitor and audit the appliance for signs of compromise and rotate any credentials stored on it.

Detection

  • Inspect HTTP request logs for img.pl requests containing shell metacharacters (;, |, `, $(), &&) in the f parameter.
  • Monitor for unexpected child processes or shell execution spawned by the web server process on the appliance.
  • Alert on outbound connections from the appliance to unusual destinations that could indicate command-and-control or data exfiltration.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-2847 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2007-1673Amavis vulnerabilityunzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a …EPSS 3.2%7.5CVE-2006-4081Barracuda networks barracuda spam firewall vulnerabilitypreview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 allows remote attackers to execute commands via shell metacharacters…EPSS 4.3%7.5CVE-2006-4001Barracuda networks barracuda spam firewall vulnerabilityLogin.pm in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 contains a hard-coded password for the guest account, which allows remote att…EPSS 1.9%7.5CVE-2005-0431Barracuda networks barracuda spam firewall vulnerabilityBarracuda Spam Firewall 3.1.10 and earlier does not restrict the domains that white-listed domains can send mail to, which allows members of white-li…EPSS 1.3%7.2CVE-2006-4082Barracuda networks barracuda spam firewall vulnerabilityBarracuda Spam Firewall (BSF), possibly 3.3.03.053, contains a hardcoded password for the admin account for logins from 127.0.0.1 (localhost), which …EPSS 0.37%6.5CVE-2008-1094Barracuda networks barracuda spam firewall sql injection vulnerabilitySQL injection vulnerability in index.cgi in the Account View page in Barracuda Spam Firewall (BSF) before 3.5.12.007 allows remote authenticated admi…EPSS 2.0%6.4CVE-2005-2849Barracuda networks barracuda spam firewall vulnerabilityArgument injection vulnerability in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to (1) read portions of source…EPSS 1.4%5.0CVE-2005-2848Barracuda networks barracuda spam firewall vulnerabilityDirectory traversal vulnerability in img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to read arbitrary f…EPSS 8.8%

Source: NIST National Vulnerability Database (record CVE-2005-2847), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.