CVE-2020-29390
zeroshell zeroshell Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2020-29390 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated attacker to execute a system command by using shell metacharacters and the %0a character.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 8, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
zeroshellBrowse zeroshell / zeroshell | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALZeroshell 3.9.3 - Command InjectionCVSS 9.8
Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated attacker to execute a system command by using shell metacharacters and the %0a character.
Impact
Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the target system.
Remediation
Upgrade to the latest version of Zeroshell or apply security patches provided by the vendor.
Source: ProjectDiscovery