Security Advisory

CVE-2019-12725

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-07-19 22:17:52
Last updated 2024-08-04 23:32:54
Assigner mitre
State PUBLISHED

Description

Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by injecting OS commands inside the vulnerable parameters.