Subscribe via feed.

ZeroShell 3.9.0 Remote Command Execution

Posted by deepcore on November 25, 2020 – 10:15 pm

This Metasploit module exploits an unauthenticated command injection vulnerability found in ZeroShell version 3.9.0 in the “/cgi-bin/kerbynet” url. As sudo is configured to execute /bin/tar without a password (NOPASSWD) it is possible to run root commands using the “checkpoint” tar options.


This post is under “exploit” and has no respond so far.
If you enjoy this article, make sure you subscribe to my RSS Feed.

Post a reply

You must be logged in to post a comment.