VYPR
Critical severity9.8NVD Advisory· Published Nov 30, 2020· Updated Jun 17, 2026

CVE-2020-29390

CVE-2020-29390

Description

Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated attacker to execute a system command by using shell metacharacters and the %0a character.

Affected products

3
  • cpe:2.3:o:zeroshell:zeroshell:3.9.3:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:zeroshell:zeroshell:3.9.3:*:*:*:*:*:*:*
    • (no CPE)range: =3.9.3
  • Zeroshell/Zeroshelldescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.