CVE Browser
CVE-2021-41738 HIGH
ZeroShell 3.9.5 has a command injection vulnerability in /cgi-bin/kerbynet IP parameter, which may allow an authenticated attacker to execute system commands.
CVSS 8.8 EPSS 1.83% Jun 11, 2022
CVE-2020-29390 CRITICAL
Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated attacker t…
CVSS 9.8 EPSS 39.56% Nov 30, 2020
CVE-2019-12725 CRITICAL
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP paramet…
CVSS 9.8 EPSS 89.85% Jul 19, 2019
CVE-2009-0545 HIGH
cgi-bin/kerbynet in ZeroShell 1.0beta11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the type parameter in a N…
CVSS 10.0 EPSS 90.39% Feb 12, 2009
Showing 1 to 4 CVEs · page 1