Sploitus

CVE-2014-6271

100 known exploits for CVE-2014-6271

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.

Gnu Bash
≤ 4.3
Fix
Available
CVSS 2.0
10.0 HIGH
CVSS 3.1
9.8 CRITICAL
EPSS
100.0% (100th percentile)
Weakness
CWE-78
NVD status
Analyzed
Published
2014-09-24
CVE-2014-6271 at NVD
Authoritative description, scoring and affected products

100 known exploits for CVE-2014-6271

Proof-of-concept code and exploit modules indexed by Sploitus

Exploit for OS Command Injection in Gnu Bash
2026-07-14 Kushiro45GITHUB
Exploit for OS Command Injection in Gnu Bash
2026-07-05 cyberexpert111GITHUB
network-vulnerability-assessment-lab
2026-06-02 Raiyan-AlifGITHUB
Exploit for OS Command Injection in Gnu Bash
2026-06-02 R3fr4ktGITHUB
unicas_docker_exploit
2026-04-27 mariomolinaraGITHUB
Exploit for OS Command Injection in Gnu Bash
2026-04-24 im2nerdGITHUB
Exploit for OS Command Injection in Gnu Bash
2026-04-09 kaleth4GITHUB
Exploit for OS Command Injection in Gnu Bash
2026-04-01 Phantom-C2-77GITHUB
Exploit for OS Command Injection in Gnu Bash
2025-12-05 DrHaithamGITHUB
Exploit for OS Command Injection in Gnu Bash
2025-09-14 mirrors_nccgroupGITEE
Exploit for OS Command Injection in Gnu Bash
2025-07-27 mirrors_albinowaxGITEE
Exploit for OS Command Injection in Gnu Bash
2025-07-27 mirrors_XiphosResearchGITEE
Apache Mod_cgi Bash Environment Variable Injection (Shellshock) Scanner
2024-09-01 Michal Zalewski, wvu, Stephane Chazelas, metasploit.comPACKETSTORMRuby
Exploit for OS Command Injection in Gnu Bash
2021-07-29 b4keSn4keGITHUB
ShellShockHunter - It's A Simple Tool For Test Vulnerability Shellshock
2021-02-10 KitPloitKITPLOIT
Qmail SMTP 1.03 - Bash Environment Variable Injection
2020-07-08 1F98DEXPLOITDBPython
xShock - Shellshock Exploit
2020-03-19 KitPloitKITPLOIT
Exploit for Out-of-bounds Read in Openssl
2019-08-19 aaaddcGITEE
Sn1per v7.0 - Automated Pentest Framework For Offensive Security Experts
2019-05-12 KitPloitKITPLOIT
Jok3R - Network And Web Pentest Framework
2019-01-23 KitPloitKITPLOIT
FutureNet NXR-G240 Series ShellShock Command Injection Exploit
2018-12-08 Nassim AsrirZDTPython
FutureNet NXR-G240 Series ShellShock Command Injection
2018-12-07 Nassim AsrirPACKETSTORMPython
Sn1per v6.0 - Automated Pentest Framework For Offensive Security Experts
2018-11-24 KitPloitKITPLOIT
Staubli Jacquard Industrial System JC6 Shellshock Vulnerability
2018-09-22 t4rkd3vilzZDT
Staubli Jacquard Industrial System JC6 Shellshock
2018-09-21 t4rkd3vilzPACKETSTORM
Sn1per v5.0 - Automated Pentest Recon Scanner
2018-07-05 KitPloitKITPLOIT
Exploit for OS Command Injection in Gnu Bash
2017-11-23 0x00-0x00GITHUB
Qmail SMTP - Bash Environment Variable Injection (Metasploit)
2017-10-02 MetasploitEXPLOITDBRuby
Qmail SMTP Bash Environment Variable Injection (Shellshock) Exploit
2017-09-30 metasploitZDTRuby
Qmail SMTP Bash Environment Variable Injection (Shellshock)
2017-09-29 Kyle GeorgePACKETSTORMRuby
Exploit for Out-of-bounds Read in Openssl
2017-07-31 fastapiGITEE
Qmail SMTP Bash Environment Variable Injection (Shellshock)
2017-05-04 Mario Ledo (Metasploit module), Gabriel Follon (Metasploit module), Kyle George (Vulnerability discovery)METASPLOITRuby
Exploit for OS Command Injection in Gnu Bash
2017-04-30 zalalovGITHUB
Exploit for OS Command Injection in Gnu Bash
2017-01-02 PortSwiggerGITHUB
RedStar 3.0 Server - BEAM & RSSMON Command Execution (Shellshock) Exploit
2016-12-19 Hacker FantasticZDTPython
RSSMON / BEAM (Red Star OS 3.0) Shellshock
2016-12-19 Hacker FantasticPACKETSTORM
RedStar 3.0 Server - Shellshock BEAM RSSMON Command Injection
2016-12-18 Hacker FantasticEXPLOITPACKPython
RedStar 3.0 Server - 'Shellshock' 'BEAM' / 'RSSMON' Command Injection
2016-12-18 Hacker FantasticEXPLOITDBPython
Exploit for OS Command Injection in Gnu Bash
2016-12-07 opsxcqGITHUB
TrendMicro InterScan Web Security Virtual Appliance - Remote Code Execution (Shellshock)
2016-10-22 Hacker FantasticZDTPython
TrendMicro InterScan Web Security Virtual Appliance Shellshock
2016-10-22 Hacker FantasticPACKETSTORM
TrendMicro InterScan Web Security Virtual Appliance - Shellshock Remote Command Injection
2016-10-21 Hacker FantasticEXPLOITPACKPython
TrendMicro InterScan Web Security Virtual Appliance - 'Shellshock' Remote Command Injection
2016-10-21 Hacker FantasticEXPLOITDBPython
IPFire - Bash Environment Variable Injection (Shellshock)
2016-06-10 metasploitZDTRuby
IPFire - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)
2016-06-10 MetasploitEXPLOITDBRuby
IPFire Bash Environment Variable Injection (Shellshock)
2016-06-09 h00diePACKETSTORMRuby
IPFire Bash Environment Variable Injection (Shellshock)
2016-05-30 h00die <mike@stcyrsecurity.com>, Claudio VivianiMETASPLOITRuby
Advantech Switch Bash Environment Variable Code Injection Exploit
2015-12-02 metasploitZDTRuby
Advantech Switch Bash Environment Variable Code Injection
2015-12-02 H D MoorePACKETSTORMRuby
Advantech Switch - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)
2015-12-02 MetasploitEXPLOITDBRuby
Advantech Switch Bash Environment Variable Code Injection (Shellshock)
2015-12-01 hdm <x@hdm.io>METASPLOITRuby
Cisco Unified Communications Manager - Multiple Vulnerabilities
2015-08-18 Bernhard MuellerEXPLOITPACK
Cisco Unified Communications Manager - Multiple Vulnerabilities
2015-08-18 Bernhard MuellerEXPLOITDB
Cisco 11.0.1 Unified Communications Manager Command Execution Vulnerability
2015-08-14 Bernhard MuellerZDT
Cisco Unified Communications Manager Command Execution
2015-08-13 Bernhard MuellerPACKETSTORM
Exploit for OS Command Injection in Gnu Bash
2015-06-26 P0cL4bsGITHUB
Kemp Load Master 7.1.16 - Multiple Vulnerabilities
2015-04-02 Roberto Suggi LiveraniEXPLOITDB
QNAP admin shell via Bash Environment Variable Code Injection Exploit
2015-03-27 Patrick PellegrinoZDTRuby
QNAP Web Server Remote Code Execution via Bash Environment Variable Code Injection Exploit
2015-03-27 Patrick PellegrinoZDTRuby
QNAP Web Server Remote Code Execution
2015-03-27 Patrick PellegrinoPACKETSTORMRuby
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
2015-03-26 Patrick PellegrinoEXPLOITPACKRuby
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
2015-03-26 Patrick PellegrinoEXPLOITPACKRuby
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
2015-03-26 Patrick PellegrinoEXPLOITDBRuby
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
2015-03-26 Patrick PellegrinoEXPLOITDBRuby
Exploit for OS Command Injection in Gnu Bash
2015-02-22 akiraaishaGITHUB
ShellShock DHCP Server
2014-11-20 SAINT CorporationSAINT
ShellShock DHCP Server
2014-11-20 SAINT CorporationSAINT
ShellShock DHCP Server
2014-11-20 SAINT CorporationSAINT
ShellShock DHCP Server
2014-11-20 SAINT CorporationSAINT
PHP 5.x - Bypass Disable Functions Vulnerability
2014-11-17 Ryan KingZDTPHP
CUPS Filter Bash Environment Variable Code Injection
2014-11-13 RootSEEBUGRuby
Bash Environment Variable Handling Shell Command Injection Via CUPS
2014-11-05 SAINT CorporationSAINT
Bash Environment Variable Handling Shell Command Injection Via CUPS
2014-11-05 SAINT CorporationSAINT
Bash Environment Variable Handling Shell Command Injection Via CUPS
2014-11-05 SAINT CorporationSAINT
Bash Environment Variable Handling Shell Command Injection Via CUPS
2014-11-05 SAINT CorporationSAINT
PHP 5.6.2 - Shellshock Safe Mode disable_functions Bypass Command Injection
2014-11-03 Ryan King (Starfall)EXPLOITPACKPHP
PHP 5.6.2 - Shellshock Safe Mode Disable Functions Bypass Command Injection
2014-11-03 Ryan King (Starfall)EXPLOITPACKPHP
PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection
2014-11-03 Ryan King (Starfall)EXPLOITDBPHP
CUPS Filter Bash Environment Variable Code Injection Exploit
2014-10-29 metasploitZDTRuby
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
2014-10-29 MetasploitEXPLOITDBRuby
CUPS Filter Bash Environment Variable Code Injection
2014-10-28 Michal ZalewskiPACKETSTORMRuby
CUPS Filter Bash Environment Variable Code Injection (Shellshock)
2014-10-19 Stephane Chazelas, lcamtuf, bcoles <bcoles@gmail.com>METASPLOITRuby
DNS Reverse Lookup Shellshock Exploit
2014-10-14 Dirk-WillemZDTC
DNS Reverse Lookup Shellshock
2014-10-13 Dirk-Willem van GulikPACKETSTORMC
OpenVPN 2.2.29 - ShellShock Exploit
2014-10-10 RootSEEBUG
Pure-FTPd External Authentication Bash Environment Variable Code Injection
2014-10-10 RootSEEBUGRuby
Bash - CGI RCE (MSF) Shellshock Exploit
2014-10-10 RootSEEBUGRuby
IPFire Cgi Web Interface Authenticated Bash Environment Variable Code Injection exploit
2014-10-10 RootSEEBUG
Bash CGI - Shellshock Remote Command Injection (Metasploit)
2014-10-06 Fady Mohammed OsmanEXPLOITPACKRuby
Apache mod_cgi Remote Command Execution
2014-10-06 Federico GalatoloPACKETSTORMPython
Postfix SMTP Shellshock
2014-10-06 fattymcwoprPACKETSTORMPython
Postfix SMTP 4.2.x < 4.2.48 - 'Shellshock' Remote Command Injection
2014-10-06 Phil BlankEXPLOITDBPython
Apache mod_cgi - 'Shellshock' Remote Command Injection
2014-10-06 Federico GalatoloEXPLOITDBPython
Bash CGI - 'Shellshock' Remote Command Injection (Metasploit)
2014-10-06 Fady Mohammed OsmanEXPLOITDBRuby
OpenVPN 2.2.29 - Shellshock Remote Command Injection
2014-10-04 hobbily pluntEXPLOITPACK
OpenVPN 2.2.29 - 'Shellshock' Remote Command Injection
2014-10-04 hobbily pluntEXPLOITDB
Shellshock Bashed CGI RCE
2014-10-03 Fady Mohamed OsmanPACKETSTORMRuby
Exploit for OS Command Injection in Gnu Bash
2014-10-03 indiandragonGITHUB
GNU bash 4.3.11 - Environment Variable dhclient
2014-10-02 @0x00stringEXPLOITDBPython
Pure-FTPd External Authentication Bash Environment Variable Code Injection Exploit
2014-10-02 metasploitZDTRuby