Записи zeroshell
4 опубликованных записей вендора zeroshell.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 25 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-20 Improper Input Validation1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
4 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
67На этой неделе | CVE-2009-0545Готовый эксплойт | cgi-bin/kerbynet in ZeroShell 1.0beta11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the tyzeroshell · zeroshell · CWE-20 | Критическая10,0 | — | 90,4 % | 12 февр. 2009 г. |
66На этой неделе | CVE-2019-12725Proof of concept | Zeroshell 3.9.0 is prone to a remote command execution vulnerability.zeroshell · zeroshell · CWE-78 | Критическая9,8 | — | 89,8 % | 19 июл. 2019 г. |
51В плане | CVE-2020-29390Proof of concept | Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthezeroshell · zeroshell · CWE-78 | Критическая9,8 | — | 39,6 % | 30 нояб. 2020 г. |
36Наблюдать | CVE-2021-41738Эксплойта нет | ZeroShell 3.9.5 has a command injection vulnerability in /cgi-bin/kerbynet IP parameter, which may allow an authenticated attacker to executzeroshell · zeroshell · CWE-78 | Высокая8,8 | — | 1,8 % | 11 июн. 2022 г. |
- CVE-2009-054567На этой неделе
cgi-bin/kerbynet in ZeroShell 1.0beta11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the ty
КритическаяCVSS 10,0Готовый эксплойтEPSS 90 %zeroshell · zeroshell12 февр. 2009 г.
- CVE-2019-1272566На этой неделе
Zeroshell 3.9.0 is prone to a remote command execution vulnerability.
КритическаяCVSS 9,8Proof of conceptEPSS 90 %zeroshell · zeroshell19 июл. 2019 г.
- CVE-2020-2939051В плане
Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthe
КритическаяCVSS 9,8Proof of conceptEPSS 40 %zeroshell · zeroshell30 нояб. 2020 г.
- CVE-2021-4173836Наблюдать
ZeroShell 3.9.5 has a command injection vulnerability in /cgi-bin/kerbynet IP parameter, which may allow an authenticated attacker to execut
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %zeroshell · zeroshell11 июн. 2022 г.