Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2019-12725-Command-Injection — Python-based proof-of-concept exploit for ZeroShell 3.9.0 remote command injection via mishandled HTTP parameters, enabling unauthenticated OS command execution. | Kitploit
Tools/GitHubGitHub/hev0x/cve-2019-12725-command-injection
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingCommand and Control
GitHubhev0x/cve-2019-12725-command-injection

CVE-2019-12725-Command-Injection

Python-based proof-of-concept exploit for ZeroShell 3.9.0 remote command injection via mishandled HTTP parameters, enabling unauthenticated OS command execution.

View Repository
2135 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

POC CVE-2019-12725-Remote-Command-Execution

ZeroShell 3.9.0 Remote Command Injection

  • Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by injecting OS commands inside the vulnerable parameters.

Exploit Usage

Commands:

$ sudo python ZeroShell_RCE.py -u <Base_Host>

  • References:

    https://www.exploit-db.com/exploits/49862

    https://packetstormsecurity.com/files/162561/ZeroShell-3.9.0-Remote-Command-Execution.html

    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12725

Download Tool