Showing 3 vulnerabilities on this page for zeroshell

Signals CISA KEV Ransomware Nuclei
zeroshell vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

zeroshell zeroshell Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated attacker to execute a system command by using shell metacharacters and the %0a character.

CWE-78Nov 30, 20201 related artifact
CVSS9.8v3.1EPSS40.2%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

zeroshell zeroshell Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by injecting OS commands inside the vulnerable parameters.

CWE-78Jul 19, 20191 related artifact
CVSS9.8v3.0EPSS89.8%PoCs8SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

zeroshell zeroshell Improper Input Validation

cgi-bin/kerbynet in ZeroShell 1.0beta11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the type parameter in a NoAuthREQ x509List action.

CWE-20Feb 12, 20091 related artifact
CVSS10.0v2.0EPSS90.4%PoCs2SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX