CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
- Affected products
- Alt Linux, Apache Http Server, Bash, Centos, Check Point Gaia, Cisco Ios Xe, Cisco Nexus, Openssh Sshd
- Gnu Bash
- ≤ 4.3
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 100.0% (100th percentile)
- Weakness
- CWE-78
- NVD status
- Analyzed
- Published
- 2014-09-24
CVE-2014-6271 at NVD
100 known exploits for CVE-2014-6271
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for OS Command Injection in Gnu Bash
Exploit for OS Command Injection in Gnu Bash
network-vulnerability-assessment-lab
Exploit for OS Command Injection in Gnu Bash
unicas_docker_exploit
Exploit for OS Command Injection in Gnu Bash
Exploit for OS Command Injection in Gnu Bash
Exploit for OS Command Injection in Gnu Bash
Exploit for OS Command Injection in Gnu Bash
Exploit for OS Command Injection in Gnu Bash
Exploit for OS Command Injection in Gnu Bash
Exploit for OS Command Injection in Gnu Bash
Apache Mod_cgi Bash Environment Variable Injection (Shellshock) Scanner
Exploit for OS Command Injection in Gnu Bash
ShellShockHunter - It's A Simple Tool For Test Vulnerability Shellshock
Qmail SMTP 1.03 - Bash Environment Variable Injection
xShock - Shellshock Exploit
Exploit for Out-of-bounds Read in Openssl
Sn1per v7.0 - Automated Pentest Framework For Offensive Security Experts
Jok3R - Network And Web Pentest Framework
FutureNet NXR-G240 Series ShellShock Command Injection Exploit
FutureNet NXR-G240 Series ShellShock Command Injection
Sn1per v6.0 - Automated Pentest Framework For Offensive Security Experts
Staubli Jacquard Industrial System JC6 Shellshock Vulnerability
Staubli Jacquard Industrial System JC6 Shellshock
Sn1per v5.0 - Automated Pentest Recon Scanner
Exploit for OS Command Injection in Gnu Bash
Qmail SMTP - Bash Environment Variable Injection (Metasploit)
Qmail SMTP Bash Environment Variable Injection (Shellshock) Exploit
Qmail SMTP Bash Environment Variable Injection (Shellshock)
Exploit for Out-of-bounds Read in Openssl
Qmail SMTP Bash Environment Variable Injection (Shellshock)
Exploit for OS Command Injection in Gnu Bash
Exploit for OS Command Injection in Gnu Bash
RedStar 3.0 Server - BEAM & RSSMON Command Execution (Shellshock) Exploit
RSSMON / BEAM (Red Star OS 3.0) Shellshock
RedStar 3.0 Server - Shellshock BEAM RSSMON Command Injection
RedStar 3.0 Server - 'Shellshock' 'BEAM' / 'RSSMON' Command Injection
Exploit for OS Command Injection in Gnu Bash
TrendMicro InterScan Web Security Virtual Appliance - Remote Code Execution (Shellshock)
TrendMicro InterScan Web Security Virtual Appliance Shellshock
TrendMicro InterScan Web Security Virtual Appliance - Shellshock Remote Command Injection
TrendMicro InterScan Web Security Virtual Appliance - 'Shellshock' Remote Command Injection
IPFire - Bash Environment Variable Injection (Shellshock)
IPFire - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)
IPFire Bash Environment Variable Injection (Shellshock)
IPFire Bash Environment Variable Injection (Shellshock)
Advantech Switch Bash Environment Variable Code Injection Exploit
Advantech Switch Bash Environment Variable Code Injection
Advantech Switch - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)
Advantech Switch Bash Environment Variable Code Injection (Shellshock)
Cisco Unified Communications Manager - Multiple Vulnerabilities
Cisco Unified Communications Manager - Multiple Vulnerabilities
Cisco 11.0.1 Unified Communications Manager Command Execution Vulnerability
Cisco Unified Communications Manager Command Execution
Exploit for OS Command Injection in Gnu Bash
Kemp Load Master 7.1.16 - Multiple Vulnerabilities
QNAP admin shell via Bash Environment Variable Code Injection Exploit
QNAP Web Server Remote Code Execution via Bash Environment Variable Code Injection Exploit
QNAP Web Server Remote Code Execution
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
Exploit for OS Command Injection in Gnu Bash
ShellShock DHCP Server
ShellShock DHCP Server
ShellShock DHCP Server
ShellShock DHCP Server
PHP 5.x - Bypass Disable Functions Vulnerability
CUPS Filter Bash Environment Variable Code Injection
Bash Environment Variable Handling Shell Command Injection Via CUPS
Bash Environment Variable Handling Shell Command Injection Via CUPS
Bash Environment Variable Handling Shell Command Injection Via CUPS
Bash Environment Variable Handling Shell Command Injection Via CUPS
PHP 5.6.2 - Shellshock Safe Mode disable_functions Bypass Command Injection
PHP 5.6.2 - Shellshock Safe Mode Disable Functions Bypass Command Injection
PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection
CUPS Filter Bash Environment Variable Code Injection Exploit
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
CUPS Filter Bash Environment Variable Code Injection
CUPS Filter Bash Environment Variable Code Injection (Shellshock)
DNS Reverse Lookup Shellshock Exploit
DNS Reverse Lookup Shellshock
OpenVPN 2.2.29 - ShellShock Exploit
Pure-FTPd External Authentication Bash Environment Variable Code Injection
Bash - CGI RCE (MSF) Shellshock Exploit
IPFire Cgi Web Interface Authenticated Bash Environment Variable Code Injection exploit
Bash CGI - Shellshock Remote Command Injection (Metasploit)
Apache mod_cgi Remote Command Execution
Postfix SMTP Shellshock
Postfix SMTP 4.2.x < 4.2.48 - 'Shellshock' Remote Command Injection
Apache mod_cgi - 'Shellshock' Remote Command Injection
Bash CGI - 'Shellshock' Remote Command Injection (Metasploit)
OpenVPN 2.2.29 - Shellshock Remote Command Injection
OpenVPN 2.2.29 - 'Shellshock' Remote Command Injection
Shellshock Bashed CGI RCE
Exploit for OS Command Injection in Gnu Bash
GNU bash 4.3.11 - Environment Variable dhclient
Pure-FTPd External Authentication Bash Environment Variable Code Injection Exploit