CVE-2019-12725
CVE-2019-12725
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by injecting OS commands inside the vulnerable parameters.
Productos afectados
n/a · n/aPoCs públicas encontradas — 10
githubgithub.com/sma11new/PocList★ 176githubgithub.com/hev0x/CVE-2019-12725-Command-Injection★ 2githubgithub.com/YZS17/CVE-2019-12725★ 1githubgithub.com/givemefivw/CVE-2019-12725★ 1githubgithub.com/t0mmy4/CVE-2019-12725-modified-exp★ 0githubgithub.com/gougou123-hash/CVE-2019-12725★ 0exploitdbwww.exploit-db.com/exploits/49862no verificadocve_referencepacketstormsecurity.com/files/162561/ZeroShell-3.9.0-Remote-Command-Execution.htmlno verificadoexploitdbwww.exploit-db.com/exploits/49096no verificadocve_referencepacketstormsecurity.com/files/160211/ZeroShell-3.9.0-Remote-Command-Execution.htmlno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →