vendor:
ZeroShell
by:
Fellipe Oliveira
9.8
CVSS
CRITICAL
Remote Command Execution
78
CWE
Product Name: ZeroShell
Affected Version From: < 3.9.0
Affected Version To: 3.9.0
Patch Exists: YES
Related CWE: CVE-2019-12725
CPE: a:zeroshell:zeroshell
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: ZeroShell 3.9.0
2021
ZeroShell 3.9.0 – Remote Command Execution
ZeroShell 3.9.0 is vulnerable to Remote Command Execution. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable server. This will allow the attacker to execute arbitrary commands on the server.
Mitigation:
Upgrade to ZeroShell 3.9.0 or later version