← back
CVE-2019-12725observed exploitation

CVE-2019-12725

87Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 90%
from disclosure to weapon494 days
Published on NVDJul 19
1st PoC+494d
VulnCheck+685d
exploitation probability
90%top 1% of all CVEs
observed exploitation
yesVulnCheck
17 public exploit(s)
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by injecting OS commands inside the vulnerable parameters.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.