CVE-2016-6903 describes a critical vulnerability in lshell version 0.9.16, allowing remote authenticated users to bypass the restricted shell and execute arbitrary commands. With a CVSS score of 9.9, this flaw presents a severe risk, as it can be exploited over the network with low complexity and user privileges, leading to complete compromise of confidentiality, integrity, and availability. While no public exploit code or Metasploit modules are available, the vulnerability has garnered some community discussion and media coverage, indicating awareness despite not being listed on the KEV catalog or actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.9.16CPE matchmatch criteria | cpe:2.3:a:lshell_project:lshell:0.9.16:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.9 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.