Heap
14-02-09, 03:40
cgi-bin/kerbynet in ZeroShell 1.0beta11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the type parameter in a NoAuthREQ x509List action.
More... (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-0545)
More... (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-0545)