.. / CVE-2009-0545

Exploit for ZeroShell <= 1.0beta11 Remote Code Execution (CVE-2009-0545)

Description:

ZeroShell 1.0beta11 and earlier via cgi-bin/kerbynet allows remote attackers to execute arbitrary commands through shell metacharacters in the type parameter in a NoAuthREQ x509List action.

Nuclei Template

View the template here CVE-2009-0545.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2009/CVE-2009-0545.yaml
Copy

References:

http://www.ikkisoft.com/stuff/LC-2009-01.txt
https://www.exploit-db.com/exploits/8023
http://www.vupen.com/english/advisories/2009/0385
http://www.zeroshell.net/eng/announcements/
https://nvd.nist.gov/vuln/detail/CVE-2009-0545