CVE-2022-39290
- EPSS 1.12%
- Published 07.10.2022 21:15:11
- Last modified 21.11.2024 07:17:58
ZoneMinder is a free, open source Closed-circuit television software application. In affected versions authenticated users can bypass CSRF keys by modifying the request supplied to the Zoneminder web application. These modifications include replacing...
CVE-2022-29806
- EPSS 88.65%
- Published 26.04.2022 04:15:42
- Last modified 21.11.2024 06:59:43
ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary pathname contributes to exploitability.
CVE-2020-25729
- EPSS 0.53%
- Published 17.09.2020 18:15:12
- Last modified 21.11.2024 05:18:35
ZoneMinder before 1.34.21 has XSS via the connkey parameter to download.php or export.php.
CVE-2019-13072
- EPSS 0.27%
- Published 30.06.2019 02:15:09
- Last modified 21.11.2024 04:24:08
Stored XSS in the Filters page (Name field) in ZoneMinder 1.32.3 allows a malicious user to embed and execute JavaScript code in the browser of any user who navigates to this page.
CVE-2019-8424
- EPSS 0.33%
- Published 18.02.2019 00:29:00
- Last modified 21.11.2024 04:49:52
ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.
CVE-2019-8423
- EPSS 0.31%
- Published 18.02.2019 00:29:00
- Last modified 21.11.2024 04:49:52
ZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter.
CVE-2019-8425
- EPSS 0.33%
- Published 18.02.2019 00:29:00
- Last modified 21.11.2024 04:49:52
includes/database.php in ZoneMinder before 1.32.3 has XSS in the construction of SQL-ERR messages.
CVE-2019-8426
- EPSS 0.33%
- Published 18.02.2019 00:29:00
- Last modified 21.11.2024 04:49:52
skins/classic/views/controlcap.php in ZoneMinder before 1.32.3 has XSS via the newControl array, as demonstrated by the newControl[MinTiltRange] parameter.
CVE-2019-8427
- EPSS 3%
- Published 18.02.2019 00:29:00
- Last modified 21.11.2024 04:49:53
daemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters.
CVE-2019-8428
- EPSS 0.33%
- Published 18.02.2019 00:29:00
- Last modified 21.11.2024 04:49:53
ZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a newGroup[MonitorIds][] value.