CVE-2020-29390

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
30/11/2020
Last modified:
03/12/2020

Description

Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated attacker to execute a system command by using shell metacharacters and the %0a character.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:zeroshell:zeroshell:3.9.3:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools