CVE-2014-6271

CRITICAL KEV NUCLEI LAB

Apache mod_cgi Bash Environment Variable Code Injection (Shellshock)

Title source: metasploit

Description

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.

Exploits (126)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotelinux
https://www.exploit-db.com/exploits/42938
exploitdb WORKING POC VERIFIED
by Hacker Fantastic · pythonlocallinux
https://www.exploit-db.com/exploits/40938
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotecgi
https://www.exploit-db.com/exploits/39918
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotecgi
https://www.exploit-db.com/exploits/38849
exploitdb WORKING POC
by Hacker Fantastic · pythonremotehardware
https://www.exploit-db.com/exploits/40619
exploitdb WRITEUP
by Bernhard Mueller · textwebappsmultiple
https://www.exploit-db.com/exploits/37816
exploitdb WORKING POC
by hobbily plunt · textremotelinux
https://www.exploit-db.com/exploits/34879
nomisec WORKING POC 228 stars
by opsxcq · remote
https://github.com/opsxcq/exploit-CVE-2014-6271
nomisec SCANNER 45 stars
by scottjpack · remote
https://github.com/scottjpack/shellshock_scanner
nomisec WORKING POC 22 stars
by hmlio · poc
https://github.com/hmlio/vaas-cve-2014-6271
nomisec WORKING POC 15 stars
by b4keSn4ke · remote
https://github.com/b4keSn4ke/CVE-2014-6271
nomisec WORKING POC 13 stars
by cj1324 · poc
https://github.com/cj1324/CGIShell
nomisec WORKING POC 12 stars
by francisck · remote
https://github.com/francisck/shellshock-cgi
nomisec SCANNER 11 stars
by indiandragon · remote
https://github.com/indiandragon/Shellshock-Vulnerability-Scan
nomisec SCANNER 6 stars
by P0cL4bs · remote
https://github.com/P0cL4bs/ShellShock-CGI-Scan
nomisec WRITEUP 6 stars
by npm · poc
https://github.com/npm/ansible-bashpocalypse
nomisec WORKING POC 5 stars
by J0hnTh3Kn1ght · poc
https://github.com/J0hnTh3Kn1ght/CVE-2014-6271
nomisec WORKING POC 4 stars
by akr3ch · remote
https://github.com/akr3ch/CVE-2014-6271
nomisec WORKING POC 4 stars
by zalalov · remote
https://github.com/zalalov/CVE-2014-6271
nomisec WORKING POC 4 stars
by securusglobal · poc
https://github.com/securusglobal/BadBash
nomisec WORKING POC 3 stars
by 0x00-0x00 · remote
https://github.com/0x00-0x00/CVE-2014-6271
nomisec WORKING POC 3 stars
by akiraaisha · remote
https://github.com/akiraaisha/shellshocker-python
nomisec WORKING POC 3 stars
by sch3m4 · poc
https://github.com/sch3m4/RIS
nomisec WORKING POC 2 stars
by K3ysTr0K3R · remote
https://github.com/K3ysTr0K3R/CVE-2014-6271-EXPLOIT
nomisec WORKING POC 2 stars
by ramnes · remote
https://github.com/ramnes/pyshellshock
nomisec WORKING POC 2 stars
by RainMak3r · poc
https://github.com/RainMak3r/Rainstorm
nomisec WORKING POC 1 stars
by im2nerd · remote
https://github.com/im2nerd/CVE-2014-6271
nomisec WORKING POC 1 stars
by RadYio · remote
https://github.com/RadYio/CVE-2014-6271
nomisec WORKING POC 1 stars
by TheRealCiscoo · remote
https://github.com/TheRealCiscoo/Shellshock-Exploit
nomisec WORKING POC 1 stars
by 0xN7y · remote
https://github.com/0xN7y/CVE-2014-6271
nomisec WORKING POC 1 stars
by Gurguii · remote
https://github.com/Gurguii/cgi-bin-shellshock
nomisec WORKING POC 1 stars
by mochizuki875 · poc
https://github.com/mochizuki875/CVE-2014-6271-Apache-Debian
nomisec WRITEUP 1 stars
by somhm-solutions · poc
https://github.com/somhm-solutions/Shell-Shock
nomisec WORKING POC 1 stars
by Any3ite · remote
https://github.com/Any3ite/CVE-2014-6271
nomisec WORKING POC 1 stars
by Anklebiter87 · poc
https://github.com/Anklebiter87/Cgi-bin_bash_Reverse
nomisec SCANNER 1 stars
by sunnyjiang · poc
https://github.com/sunnyjiang/shellshocker-android
nomisec SCANNER 1 stars
by ryeyao · remote
https://github.com/ryeyao/CVE-2014-6271_Test
nomisec SCANNER 1 stars
by gabemarshall · poc
https://github.com/gabemarshall/shocknaww
nomisec SCANNER 1 stars
by proclnas · remote
https://github.com/proclnas/ShellShock-CGI-Scan
nomisec SCANNER 1 stars
by themson · remote
https://github.com/themson/shellshock
nomisec WORKING POC 1 stars
by APSL · poc
https://github.com/APSL/salt-shellshock
nomisec SCANNER
by kaleth4 · poc
https://github.com/kaleth4/CVE-2014-6271
nomisec WRITEUP
by kaleth4 · poc
https://github.com/kaleth4/-CVE-2014-6271
nomisec WRITEUP
by ambjlou · poc
https://github.com/ambjlou/it355-lab4-enterprise-lan-security
nomisec WORKING POC
by 0xBlackash · poc
https://github.com/0xBlackash/CVE-2014-6271
nomisec WORKING POC
by 0xAshwesker · poc
https://github.com/0xAshwesker/CVE-2014-6271
nomisec WORKING POC
by Industri4l-H3ll-Xpl0it3rs · remote
https://github.com/Industri4l-H3ll-Xpl0it3rs/CVE-2014-6271-Shellshock
nomisec NO CODE
by andres101c · poc
https://github.com/andres101c/Shellshock-CVE-2014-6271
nomisec WORKING POC
by mtaha-sec · poc
https://github.com/mtaha-sec/bash-apocalypse
nomisec WORKING POC
by DrHaitham · poc
https://github.com/DrHaitham/CVE-2014-6271-Shellshock-
github WRITEUP
by OscarYR · poc
https://github.com/OscarYR/CVE_Reproduction/tree/main/Shellshock/CVE-2014-6271.md
nomisec WRITEUP
by RAJMadhusankha · poc
https://github.com/RAJMadhusankha/Shellshock-CVE-2014-6271-Exploitation-and-Analysis
nomisec WORKING POC
by rsherstnev · remote
https://github.com/rsherstnev/CVE-2014-6271
nomisec WORKING POC
by knightc0de · remote
https://github.com/knightc0de/Shellshock_vuln_Exploit
nomisec SCANNER
by moften · remote
https://github.com/moften/CVE-2014-6271
nomisec WORKING POC
by YunchoHang · remote
https://github.com/YunchoHang/CVE-2014-6271-SHELLSHOCK
nomisec WORKING POC
by AlissonFaoli · remote
https://github.com/AlissonFaoli/Shellshock
nomisec SCANNER
by ajansha · remote
https://github.com/ajansha/shellshock
nomisec WORKING POC
by hanmin0512 · poc
https://github.com/hanmin0512/CVE-2014-6271_pwnable
nomisec SCANNER
by Brandaoo · remote
https://github.com/Brandaoo/CVE-2014-6271
nomisec WORKING POC
by mritunjay-k · remote
https://github.com/mritunjay-k/CVE-2014-6271
nomisec WORKING POC
by hadrian3689 · remote
https://github.com/hadrian3689/shellshock
nomisec WORKING POC
by FilipStudeny · remote
https://github.com/FilipStudeny/-CVE-2014-6271-Shellshock-Remote-Command-Injection-
nomisec WORKING POC
by anujbhan · poc
https://github.com/anujbhan/shellshock-victim-host
nomisec WRITEUP
by cved-sources · poc
https://github.com/cved-sources/cve-2014-6271
nomisec WORKING POC
by MuirlandOracle · remote
https://github.com/MuirlandOracle/CVE-2014-6271-IPFire
nomisec WORKING POC
by cyberharsh · poc
https://github.com/cyberharsh/Shellbash-CVE-2014-6271
nomisec STUB
by Dilith006 · poc
https://github.com/Dilith006/CVE-2014-6271
nomisec WRITEUP
by rashmikadileeshara · poc
https://github.com/rashmikadileeshara/CVE-2014-6271-Shellshock-
nomisec NO CODE
by Sindayifu · poc
https://github.com/Sindayifu/CVE-2019-14287-CVE-2014-6271
nomisec NO CODE
by wenyu1999 · poc
https://github.com/wenyu1999/bash-shellshock
nomisec NO CODE
by Sindadziy · poc
https://github.com/Sindadziy/cve-2014-6271
nomisec WORKING POC
by shawntns · remote
https://github.com/shawntns/exploit-CVE-2014-6271
nomisec WORKING POC
by Aruthw · poc
https://github.com/Aruthw/CVE-2014-6271
nomisec WORKING POC
by w4fz5uck5 · remote
https://github.com/w4fz5uck5/ShockZaum-CVE-2014-6271
nomisec WORKING POC
by kowshik-sundararajan · poc
https://github.com/kowshik-sundararajan/CVE-2014-6271
nomisec SCANNER
by ilismal · poc
https://github.com/ilismal/Nessus_CVE-2014-6271_check
nomisec WORKING POC
by Pilou-Pilou · poc
https://github.com/Pilou-Pilou/docker_CVE-2014-6271.
nomisec STUB
by huanlu · poc
https://github.com/huanlu/cve-2014-6271-huan-lu
nomisec NO CODE
by kelleykong · poc
https://github.com/kelleykong/cve-2014-6271-mengjia-kong
nomisec WORKING POC
by heikipikker · remote
https://github.com/heikipikker/shellshock-shell
nomisec SCANNER
by teedeedubya · poc
https://github.com/teedeedubya/bash-fix-exploit
nomisec SCANNER
by renanvicente · poc
https://github.com/renanvicente/puppet-shellshock
nomisec NO CODE
by ariarijp · poc
https://github.com/ariarijp/vagrant-shellshock
nomisec WRITEUP
by u20024804 · remote
https://github.com/u20024804/bash-4.3-fixed-CVE-2014-6271
nomisec WRITEUP
by u20024804 · remote
https://github.com/u20024804/bash-4.2-fixed-CVE-2014-6271
nomisec STUB
by u20024804 · remote
https://github.com/u20024804/bash-3.2-fixed-CVE-2014-6271
nomisec SCANNER
by 352926 · remote
https://github.com/352926/shellshock_crawler
nomisec WORKING POC
by ryancnelson · poc
https://github.com/ryancnelson/patched-bash-4.3
nomisec WRITEUP
by internero · poc
https://github.com/internero/debian-lenny-bash_3.2.52-cve-2014-6271
nomisec WORKING POC
by woltage · poc
https://github.com/woltage/CVE-2014-6271
nomisec SCANNER
by villadora · remote
https://github.com/villadora/CVE-2014-6271
nomisec SCANNER
by jblaine · remote
https://github.com/jblaine/cookbook-bash-CVE-2014-6271
nomisec WORKING POC
by mattclegg · poc
https://github.com/mattclegg/CVE-2014-6271
nomisec STUB
by justzx2011 · poc
https://github.com/justzx2011/bash-up
nomisec SCANNER
by rrreeeyyy · poc
https://github.com/rrreeeyyy/cve-2014-6271-spec
nomisec WRITEUP
by dlitz · poc
https://github.com/dlitz/bash-cve-2014-6271-fixes
metasploit SCANNER
by Stephane Chazelas, wvu, lcamtuf · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/apache_mod_cgi_bash_env.rb
vulncheck_xdb WORKING POC
remote
https://github.com/Jsmoreira02/CVE-2014-6271
vulncheck_xdb WORKING POC
remote
https://github.com/17moonup/CVE
vulncheck_xdb SUSPICIOUS
remote
https://github.com/l0veormiss/l0veormiss.github.io
vulncheck_xdb WORKING POC
remote
https://github.com/darrenmartyn/VisualDoor
vulncheck_xdb WORKING POC
remote-auth
https://github.com/threat9/routersploit
exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/35146
exploitdb WRITEUP
webappsmultiple
https://www.exploit-db.com/exploits/36609
exploitdb WORKING POC
rubyremotelinux
https://www.exploit-db.com/exploits/34862
exploitdb WORKING POC
pythonremotelinux
https://www.exploit-db.com/exploits/34896
exploitdb WORKING POC
pythonremotelinux
https://www.exploit-db.com/exploits/34860
exploitdb WRITEUP
remotelinux
https://www.exploit-db.com/exploits/34765
exploitdb WORKING POC
rubyremotelinux
https://www.exploit-db.com/exploits/35115
exploitdb WORKING POC
phpremotelinux
https://www.exploit-db.com/exploits/34766
exploitdb WORKING POC
pythonremotelinux
https://www.exploit-db.com/exploits/34900
exploitdb WORKING POC
rubyremotehardware
https://www.exploit-db.com/exploits/36504
exploitdb WORKING POC
rubyremotehardware
https://www.exploit-db.com/exploits/36503
exploitdb WORKING POC
pythonwebappscgi
https://www.exploit-db.com/exploits/34839
exploitdb WORKING POC
rubywebappscgi
https://www.exploit-db.com/exploits/34895
exploitdb WORKING POC
rubyremotecgi
https://www.exploit-db.com/exploits/34777
metasploit WORKING POC
by scriptjunkie · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/server/dhclient_bash_env.rb
metasploit WORKING POC NORMAL
by Mario Ledo (Metasploit module), Gabriel Follon (Metasploit module), Kyle George (Vulnerability discovery) · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/smtp/qmail_bash_env_exec.rb
metasploit WORKING POC EXCELLENT
by Stephane Chazelas, egypt · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/dhcp/bash_environment.rb
metasploit WORKING POC EXCELLENT
by Stephane Chazelas, Frank Denis, Spencer McIntyre · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/ftp/pureftpd_bash_env_exec.rb
metasploit WORKING POC EXCELLENT
by h00die <[email protected]>, Claudio Viviani · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/ipfire_bashbug_exec.rb
metasploit WORKING POC EXCELLENT
rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/advantech_switch_bash_env_exec.rb
metasploit WORKING POC NORMAL
by Stephane Chazelas, juken, joev, mubix · rubypocosx
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/osx/local/vmware_bash_function_root.rb

Nuclei Templates (1)

ShellShock - Remote Code Execution
CRITICALby pentest_swissky,0xelkomy

References (171)

... and 151 more

Scores

CVSS v3 9.8
EPSS 0.9422
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Lab Environment

COMMUNITY
Community Lab
docker pull httpd:2.2
docker pull mochizuki875/cve-2014-6271-apache-debian:buster
docker pull httpd:2.4.48-alpine
docker pull fnichol/uhttpd
docker pull vulhub/openssl:1.0.1c-with-nginx
+99 more repos

Details

CISA KEV 2022-01-28
VulnCheck KEV 2014-09-30
InTheWild.io 2022-01-28
ENISA EUVD EUVD-2014-6157
CWE
CWE-78
Status published
Products (49)
apple/mac_os_x 10.0.0 - 10.10.0
arista/eos 4.9.0 - 4.9.12
canonical/ubuntu_linux 10.04
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 14.04
checkpoint/security_gateway < r77.30
citrix/netscaler_sdx_firmware < 9.3.67.5r1
debian/debian_linux 7.0
f5/arx_firmware 6.0.0 - 6.4.0
f5/big-ip_access_policy_manager 11.6.0
... and 39 more
Published Sep 24, 2014
KEV Added Jan 28, 2022
Tracked Since Feb 18, 2026