CVE-2020-25729
- EPSS 1.21%
- Veröffentlicht 17.09.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:35
ZoneMinder before 1.34.21 has XSS via the connkey parameter to download.php or export.php.
CVE-2019-13072
- EPSS 0.86%
- Veröffentlicht 30.06.2019 02:15:09
- Zuletzt bearbeitet 21.11.2024 04:24:08
Stored XSS in the Filters page (Name field) in ZoneMinder 1.32.3 allows a malicious user to embed and execute JavaScript code in the browser of any user who navigates to this page.
CVE-2019-8429
- EPSS 1.65%
- Veröffentlicht 18.02.2019 00:29:00
- Zuletzt bearbeitet 21.11.2024 04:49:53
ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php filter[Query][terms][0][cnj] parameter.
CVE-2019-8428
- EPSS 1.6%
- Veröffentlicht 18.02.2019 00:29:00
- Zuletzt bearbeitet 21.11.2024 04:49:53
ZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a newGroup[MonitorIds][] value.
CVE-2019-8427
- EPSS 2.49%
- Veröffentlicht 18.02.2019 00:29:00
- Zuletzt bearbeitet 21.11.2024 04:49:53
daemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters.
CVE-2019-8426
- EPSS 0.97%
- Veröffentlicht 18.02.2019 00:29:00
- Zuletzt bearbeitet 21.11.2024 04:49:52
skins/classic/views/controlcap.php in ZoneMinder before 1.32.3 has XSS via the newControl array, as demonstrated by the newControl[MinTiltRange] parameter.
CVE-2019-8425
- EPSS 0.97%
- Veröffentlicht 18.02.2019 00:29:00
- Zuletzt bearbeitet 21.11.2024 04:49:52
includes/database.php in ZoneMinder before 1.32.3 has XSS in the construction of SQL-ERR messages.
CVE-2019-8424
- EPSS 1.6%
- Veröffentlicht 18.02.2019 00:29:00
- Zuletzt bearbeitet 21.11.2024 04:49:52
ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.
CVE-2019-8423
- EPSS 1.61%
- Veröffentlicht 18.02.2019 00:29:00
- Zuletzt bearbeitet 21.11.2024 04:49:52
ZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter.
CVE-2019-7347
- EPSS 0.91%
- Veröffentlicht 04.02.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 04:48:04
A Time-of-check Time-of-use (TOCTOU) Race Condition exists in ZoneMinder through 1.32.3 as a session remains active for an authenticated user even after deletion from the users table. This allows a nonexistent user to access and modify records (add/d...