CVE-2013-2097

HIGH

ZPanel <10.1.0 - RCE

Title source: llm

Description

ZPanel through 10.1.0 has Remote Command Execution

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotephp
https://www.exploit-db.com/exploits/38505
exploitdb WRITEUP
by Sven Slootweg · textwebappsphp
https://www.exploit-db.com/exploits/25519
metasploit WORKING POC EXCELLENT
by Balazs Makany, Jose Antonio Perez, dawn isabel, brad wolfe, brent morris, james fitts · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/zpanel_information_disclosure_rce.rb

Scores

CVSS v3 7.8
EPSS 0.6295
EPSS Percentile 98.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
zpanel_project/zpanel 10.1.0
Published Feb 12, 2020
Tracked Since Feb 18, 2026