CVE-2012-10039 - CVE House
Back to Database
Status published Critical CVE-2012-10039

ZEN Load Balancer Filelog Command Execution

Vulnerability Description

ZEN Load Balancer versions 2.0 and 3.0-rc1 contain a command injection vulnerability in content2-2.cgi. The filelog parameter is passed directly into a backtick-delimited exec() call without sanitation. An authenticated attacker can inject arbitrary shell commands, resulting in remote code execution as the root user. ZEN Load Balancer is the predecessor of ZEVENET and SKUDONET. The affected versions (2.0 and 3.0-rc1) are no longer supported. SKUDONET CE is the current community-maintained successor.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-10039

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • bcoles

Affected Vendor

ZEN Load Balancer

View all reports →

Affected Software

ZEN Load Balancer
Vulnerable Versions:
2.0, 3.0-rc1

Timeline

Official Publish: August 11th, 2025
Last Modified: April 7th, 2026
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)