Zeroshell是一套面向服务器和嵌入式系统的Linux发行版。 Zeroshell 3.9.3版本存在操作系统命令注入漏洞,该漏洞源于在cgi-bin kerbynet StartSessionSubmit参数中包含一个命令注入漏洞,该漏洞允许未经身份验证的攻击者可利用该漏洞使用shell元字符和字符执行系统命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated attacker to execute a system command by using shell metacharacters and the %0a character. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-29390.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-29441 | 7.2 HIGH | Outsystems OutSystems Platform 代码问题漏洞 |
| CVE-2020-27585 | K7 Computing Quick Heal Total Security 安全漏洞 | |
| CVE-2020-29394 | Genvini Dlt-daemon 缓冲区错误漏洞 | |
| CVE-2020-25624 | QEMU 缓冲区错误漏洞 | |
| CVE-2020-29127 | Fujitsu Eternus Storage DX200 S4 授权问题漏洞 | |
| CVE-2020-28976 | WordPress Canto plugin 代码问题漏洞 | |
| CVE-2020-28977 | WordPress Canto plugin 代码问题漏洞 | |
| CVE-2020-28978 | WordPress Canto plugin 代码问题漏洞 | |
| CVE-2020-29384 | Pngout 输入验证错误漏洞 | |
| CVE-2020-28926 | ReadyMedia 安全漏洞 | |
| CVE-2020-25537 | UCMS 代码问题漏洞 | |
| CVE-2020-29364 | NetArt News Lister 跨站脚本漏洞 | |
| CVE-2020-29392 | Estil Hill Lock Password Manager Safe app 安全漏洞 | |
| CVE-2020-17901 | PbootCMS 跨站请求伪造漏洞 | |
| CVE-2020-29395 | WordPress plugin 跨站脚本漏洞 | |
| CVE-2020-9115 | Huawei ManageOne 输入验证错误漏洞 | |
| CVE-2020-27586 | K7 Computing Total Security 安全漏洞 | |
| CVE-2020-27587 | K7 Computing Quick Heal Total Security 安全漏洞 | |
| CVE-2020-11867 | Audacity 安全漏洞 | |
| CVE-2020-29440 | Tesla Model X 信任管理问题漏洞 |
Showing top 20 of 29 CVEs. View all on vendor page → →
No comments yet