Zoneminder

Zoneminder

92 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.21%
  • Veröffentlicht 17.09.2020 18:15:12
  • Zuletzt bearbeitet 21.11.2024 05:18:35

ZoneMinder before 1.34.21 has XSS via the connkey parameter to download.php or export.php.

Exploit
  • EPSS 0.86%
  • Veröffentlicht 30.06.2019 02:15:09
  • Zuletzt bearbeitet 21.11.2024 04:24:08

Stored XSS in the Filters page (Name field) in ZoneMinder 1.32.3 allows a malicious user to embed and execute JavaScript code in the browser of any user who navigates to this page.

Exploit
  • EPSS 1.65%
  • Veröffentlicht 18.02.2019 00:29:00
  • Zuletzt bearbeitet 21.11.2024 04:49:53

ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php filter[Query][terms][0][cnj] parameter.

Exploit
  • EPSS 1.6%
  • Veröffentlicht 18.02.2019 00:29:00
  • Zuletzt bearbeitet 21.11.2024 04:49:53

ZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a newGroup[MonitorIds][] value.

Exploit
  • EPSS 2.49%
  • Veröffentlicht 18.02.2019 00:29:00
  • Zuletzt bearbeitet 21.11.2024 04:49:53

daemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters.

Exploit
  • EPSS 0.97%
  • Veröffentlicht 18.02.2019 00:29:00
  • Zuletzt bearbeitet 21.11.2024 04:49:52

skins/classic/views/controlcap.php in ZoneMinder before 1.32.3 has XSS via the newControl array, as demonstrated by the newControl[MinTiltRange] parameter.

Exploit
  • EPSS 0.97%
  • Veröffentlicht 18.02.2019 00:29:00
  • Zuletzt bearbeitet 21.11.2024 04:49:52

includes/database.php in ZoneMinder before 1.32.3 has XSS in the construction of SQL-ERR messages.

Exploit
  • EPSS 1.6%
  • Veröffentlicht 18.02.2019 00:29:00
  • Zuletzt bearbeitet 21.11.2024 04:49:52

ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.

Exploit
  • EPSS 1.61%
  • Veröffentlicht 18.02.2019 00:29:00
  • Zuletzt bearbeitet 21.11.2024 04:49:52

ZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter.

Exploit
  • EPSS 0.91%
  • Veröffentlicht 04.02.2019 19:29:01
  • Zuletzt bearbeitet 21.11.2024 04:48:04

A Time-of-check Time-of-use (TOCTOU) Race Condition exists in ZoneMinder through 1.32.3 as a session remains active for an authenticated user even after deletion from the users table. This allows a nonexistent user to access and modify records (add/d...