10

CVE-2009-0545

Exploit
cgi-bin/kerbynet in ZeroShell 1.0beta11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the type parameter in a NoAuthREQ x509List action.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zeroshell ≫ Zeroshell Version 1.0 Update beta1
Zeroshell ≫ Zeroshell Version 1.0 Update beta10
Zeroshell ≫ Zeroshell Version 1.0 Update beta11
Zeroshell ≫ Zeroshell Version 1.0 Update beta2
Zeroshell ≫ Zeroshell Version 1.0 Update beta3
Zeroshell ≫ Zeroshell Version 1.0 Update beta4
Zeroshell ≫ Zeroshell Version 1.0 Update beta5
Zeroshell ≫ Zeroshell Version 1.0 Update beta6
Zeroshell ≫ Zeroshell Version 1.0 Update beta7
Zeroshell ≫ Zeroshell Version 1.0 Update beta8
Zeroshell ≫ Zeroshell Version 1.0 Update beta9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 90.39% 0.998
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.ikkisoft.com/stuff/LC-2009-01.txt
Exploit
http://www.securityfocus.com/archive/1/500763/100/0/threaded
http://www.vupen.com/english/advisories/2009/0385
http://www.zeroshell.net/eng/announcements/
Patch
Vendor Advisory
http://www.zeroshell.net/eng/patch-details/#C100
Patch
https://www.exploit-db.com/exploits/8023