header-logo
Suggest Exploit
vendor:
ZeroShell
by:
Fellipe Oliveira
9.8
CVSS
CRITICAL
Remote Command Execution
78
CWE
Product Name: ZeroShell
Affected Version From: < 3.9.0
Affected Version To: 3.9.0
Patch Exists: YES
Related CWE: CVE-2019-12725
CPE: a:zeroshell:zeroshell
Metasploit: N/A
Other Scripts: N/A
Platforms Tested: ZeroShell 3.9.0
2021

ZeroShell 3.9.0 – Remote Command Execution

ZeroShell 3.9.0 is vulnerable to Remote Command Execution. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable server. This will allow the attacker to execute arbitrary commands on the server.

Mitigation:

Upgrade to ZeroShell 3.9.0 or later version
Source

Exploit-DB raw data: