This Metasploit module exploits an unauthenticated command injection vulnerability found in ZeroShell version 3.9.0 in the "/cgi-bin/kerbynet" url. As sudo is configured to execute /bin/tar without a password (NOPASSWD) it is possible to run root commands using the "checkpoint" tar options.
e52e0c15527e1e5b23e1a5f32e17df46f22d8f0dc8643606d04c891cd43c603d
Whitepaper called Paraisiting web server process with webshells in permissive environments.
4afa9eda25fe12a978a6d2a45d2b5514b98cca6fd971be9525f63c9fac79cbc5