Zoneminder

Zoneminder

84 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.12%
  • Published 07.10.2022 21:15:11
  • Last modified 21.11.2024 07:17:58

ZoneMinder is a free, open source Closed-circuit television software application. In affected versions authenticated users can bypass CSRF keys by modifying the request supplied to the Zoneminder web application. These modifications include replacing...

Exploit
  • EPSS 88.65%
  • Published 26.04.2022 04:15:42
  • Last modified 21.11.2024 06:59:43

ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary pathname contributes to exploitability.

  • EPSS 0.53%
  • Published 17.09.2020 18:15:12
  • Last modified 21.11.2024 05:18:35

ZoneMinder before 1.34.21 has XSS via the connkey parameter to download.php or export.php.

Exploit
  • EPSS 0.27%
  • Published 30.06.2019 02:15:09
  • Last modified 21.11.2024 04:24:08

Stored XSS in the Filters page (Name field) in ZoneMinder 1.32.3 allows a malicious user to embed and execute JavaScript code in the browser of any user who navigates to this page.

Exploit
  • EPSS 0.33%
  • Published 18.02.2019 00:29:00
  • Last modified 21.11.2024 04:49:52

ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.

Exploit
  • EPSS 0.31%
  • Published 18.02.2019 00:29:00
  • Last modified 21.11.2024 04:49:52

ZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter.

Exploit
  • EPSS 0.33%
  • Published 18.02.2019 00:29:00
  • Last modified 21.11.2024 04:49:52

includes/database.php in ZoneMinder before 1.32.3 has XSS in the construction of SQL-ERR messages.

Exploit
  • EPSS 0.33%
  • Published 18.02.2019 00:29:00
  • Last modified 21.11.2024 04:49:52

skins/classic/views/controlcap.php in ZoneMinder before 1.32.3 has XSS via the newControl array, as demonstrated by the newControl[MinTiltRange] parameter.

Exploit
  • EPSS 3%
  • Published 18.02.2019 00:29:00
  • Last modified 21.11.2024 04:49:53

daemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters.

Exploit
  • EPSS 0.33%
  • Published 18.02.2019 00:29:00
  • Last modified 21.11.2024 04:49:53

ZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a newGroup[MonitorIds][] value.