{"id":"CVE-2020-13167","aliases":[],"url":"https://o3.security/vulnerability/CVE-2020-13167","summary":"Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches a command line with client-supplied…","details":"Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches a command line with client-supplied parameters, and allows injection of shell metacharacters.","published":"2020-05-19T20:15:10.147","modified":"2026-06-17T02:52:43.633","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.95415,"percentile":0.99861,"asOf":"2026-08-27"},"cisaKev":null,"exploitsKnown":2,"affectedPackages":[],"fix":null,"references":[{"type":"EXPLOIT","url":"https://ssd-disclosure.com/ssd-advisory-netsweeper-preauth-rce/"},{"type":"EXPLOIT","url":"https://ssd-disclosure.com/ssd-advisory-netsweeper-preauth-rce/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T02:52:43.633"}}