ZEN Load Balancer Filelog Command Execution
Vulnerability Description
ZEN Load Balancer versions 2.0 and 3.0-rc1 contain a command injection vulnerability in content2-2.cgi. The filelog parameter is passed directly into a backtick-delimited exec() call without sanitation. An authenticated attacker can inject arbitrary shell commands, resulting in remote code execution as the root user. ZEN Load Balancer is the predecessor of ZEVENET and SKUDONET. The affected versions (2.0 and 3.0-rc1) are no longer supported. SKUDONET CE is the current community-maintained successor.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-10039
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- bcoles
References
- https://web.archive.org/web/20221203195056/https://itsecuritysolutions.org/2012-09-21-ZEN-Load-Balancer-v2.0-and-v3.0-rc1-multiple-vulnerabilities/
- https://web.archive.org/web/20111015031540/http://www.zenloadbalancer.com/
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/http/zen_load_balancer_exec.rb
- https://www.exploit-db.com/exploits/21849
- https://www.fortiguard.com/encyclopedia/ips/33335/zen-load-balancer-filelog-command-execution
Affected Vendor
ZEN Load Balancer
View all reports →