CVE-2019-12725
87Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 90%
from disclosure to weapon494 days
Published on NVDJul 19
1st PoC+494d
VulnCheck+685d
exploitation probability
90%top 1% of all CVEs
observed exploitation
yesVulnCheck
17 public exploit(s)
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by injecting OS commands inside the vulnerable parameters.
Affected products
n/a · n/apublic PoCs found — 17✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/49096exploitdbwww.exploit-db.com/exploits/49862unverifiedgithubgithub.com/sma11new/PocList★ 176githubgithub.com/hev0x/CVE-2019-12725-Command-Injection★ 2githubgithub.com/YZS17/CVE-2019-12725★ 1githubgithub.com/givemefivw/CVE-2019-12725★ 1githubgithub.com/gougou123-hash/CVE-2019-12725★ 0githubgithub.com/t0mmy4/CVE-2019-12725-modified-exp★ 0cve_referencepacketstormsecurity.com/files/160211/ZeroShell-3.9.0-Remote-Command-Execution.htmlunverifiedvulncheckvulncheck.com/xdb/2ff79e5dba12unverifiedcve_referencepacketstormsecurity.com/files/162561/ZeroShell-3.9.0-Remote-Command-Execution.htmlunverifiedvulncheckvulncheck.com/xdb/4c966affbe66unverifiedvulncheckvulncheck.com/xdb/bdb64363e245unverifiedvulncheckvulncheck.com/xdb/12438cb6d95funverifiedvulncheckvulncheck.com/xdb/b19f9a0ae4e3unverifiedvulncheckvulncheck.com/xdb/06d81050cb01unverifiedvulncheckvulncheck.com/xdb/667271afebf2unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.