CVE-2010-20109 - CVE House
Back to Database
Status published High CVE-2010-20109

Barracuda Spam & Virus Firewall "locale" Path Traversal

Vulnerability Description

Barracuda products, confirmed in Spam & Virus Firewall, SSL VPN, and Web Application Firewall versions prior to October 2010, contain a path traversal vulnerability in the view_help.cgi endpoint. The locale parameter fails to properly sanitize user input, allowing attackers to inject traversal sequences and null-byte terminators to access arbitrary files on the underlying system. By exploiting this flaw, unauthenticated remote attackers can retrieve sensitive configuration files such as /mail/snapshot/config.snapshot, potentially exposing credentials, internal settings, and other critical data.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-20109

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • ShadowHatesYou

Affected Vendor

Barracuda Networks

View all reports →

Affected Software

Spam & Virus Firewall, SSL VPN, Web Application Firewall
Vulnerable Versions:
0

Timeline

Official Publish: August 21st, 2025
Last Modified: May 26th, 2026
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)