Loading
Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated attacker to execute a system command by using shell metacharacters and the %0a character.
Use CWE-78, Zeroshell vendor hub and Zeroshell product page to widen CVE-2020-29390 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2009-0545, CVE-2019-12725 and CVE-2021-41738 for nearby disclosures in the same product family.