Motioneye Project

Motioneye

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.42%
  • Veröffentlicht 24.06.2026 21:16:53
  • Zuletzt bearbeitet 25.06.2026 23:17:02

motionEye (mEye) is an online interface for motion software, which is a video surveillance program with motion detection. Versions prior to 0.44.0 are vulnerable to path traversal in the picture and movie API endpoints, suhc as /picture/{id}/preview/...

  • EPSS 2.9%
  • Veröffentlicht 24.06.2026 21:16:53
  • Zuletzt bearbeitet 25.06.2026 18:56:54

motionEye (mEye) is an online interface for motion software, a video surveillance program with motion detection. Versions prior to 0.44.0 create the configuration file /etc/motioneye/motion.conf with 644 permissions (-rw-r--r--), making it readable b...

  • EPSS 0.62%
  • Veröffentlicht 24.06.2026 15:03:26
  • Zuletzt bearbeitet 25.06.2026 18:56:54

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Versions prior to 0.44.0 contain an absolute path traversal vulnerability in multiple media file handlers th...

Exploit
  • EPSS 24.75%
  • Veröffentlicht 03.10.2025 00:00:00
  • Zuletzt bearbeitet 10.10.2025 16:22:30

MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is written to Motion configuration files, allowing remote authenticated attackers with admin access to ac...

  • EPSS 0.41%
  • Veröffentlicht 14.05.2025 16:15:29
  • Zuletzt bearbeitet 15.04.2026 00:35:42

motionEye is an online interface for the software motion, a video surveillance program with motion detection. In versions 0.43.1b1 through 0.43.1b3, using a constructed (camera) device path with the `add`/`add_camera` motionEye web API allows an atta...

Exploit
  • EPSS 6.83%
  • Veröffentlicht 24.03.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 06:52:22

MotionEye v0.42.1 and below allows attackers to access sensitive information via a GET request to /config/list. To exploit this vulnerability, a regular user password must be unconfigured.

  • EPSS 2.95%
  • Veröffentlicht 31.01.2022 12:15:07
  • Zuletzt bearbeitet 21.11.2024 06:30:40

Authenticated remote code execution in MotionEye <= 0.42.1 and MotioneEyeOS <= 20200606 allows a remote attacker to upload a configuration backup file containing a malicious python pickle file which will execute arbitrary code on the server.