CVE-2019-12725 Information
Feb 14, 2021
cve
Description
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by injecting OS commands inside the vulnerable parameters.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://www.tarlogic.com/advisories/zeroshell-rce-root.txt https://zeroshell.org/blog/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Hosts Detected Exploiting in the Wild
103.44.245.166 103.76.228.45 119.29.242.180 121.7.36.20 128.106.166.8 139.59.94.33 149.129.131.134 149.129.139.238 149.129.139.48 172.98.64.135 183.220.138.20 190.215.113.98 219.74.237.196 31.207.35.138 39.98.57.48 5.44.100.108 65.157.48.186 8.129.209.71
Share on: