CVE-2020-29390

Publication date

2020-11-30 17:24:17

Family

mitre

State

PUBLISHED

Description

Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated attacker to execute a system command by using shell metacharacters and the %0a character.