Loading
cgi-bin/kerbynet in ZeroShell 1.0beta11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the type parameter in a NoAuthREQ x509List action.
Use CWE-20, Zeroshell vendor hub and Zeroshell product page to widen CVE-2009-0545 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-29390, CVE-2019-12725 and CVE-2021-41738 for nearby disclosures in the same product family.