Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by injecting OS commands inside the vulnerable parameters.
PoC: PocList
漏洞POC、EXP合集,持续更新。Apache Druid-任意文件读取(CVE-2021-36749)、ConfluenceRCE(CVE-2021-26084)、ZeroShell防火墙RCE(CVE-2019-12725)、ApacheSolr任意文件读取、蓝凌OA任意文件读取、phpStudyRCE、ShowDoc任意文件上传、原创先锋后台未授权、Kyan账号密码泄露、TerraMasterTos任意文件读取、TamronOS-IPTV系统RCE、Wayos防火墙账号密码泄露
PoC: CVE-2019-12725
The EXP/POC of CVE-2019-12725
PoC: CVE-2019-12725
ZeroShell命令执行漏洞批量扫描poc+exp
PoC: CVE-2019-12725-Command-Injection
ZeroShell 3.9.0 Remote Command Injection
PoC: CVE-2019-12725
CVE-2019-12725 ZeroShell 远程命令执行漏洞
PoC: CVE-2019-12725
ZeroShell命令执行漏洞批量扫描poc+exp
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free