CVE-2020-29390
30.11.2020, 18:15
Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated attacker to execute a system command by using shell metacharacters and the %0a character.
Vendor | Product | Version |
---|---|---|
zeroshell | zeroshell | 3.9.3 |
𝑥
= Vulnerable software versions