CVE-2021-41738

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
11/06/2022
Last modified:
07/11/2023

Description

ZeroShell 3.9.5 has a command injection vulnerability in /cgi-bin/kerbynet IP parameter, which may allow an authenticated attacker to execute system commands.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:zeroshell:zeroshell:3.9.5:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools