CVE-2019-7347
- EPSS 0.91%
- Veröffentlicht 04.02.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 04:48:04
A Time-of-check Time-of-use (TOCTOU) Race Condition exists in ZoneMinder through 1.32.3 as a session remains active for an authenticated user even after deletion from the users table. This allows a nonexistent user to access and modify records (add/d...
CVE-2019-7346
- EPSS 0.66%
- Veröffentlicht 04.02.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 04:48:03
A CSRF check issue exists in ZoneMinder through 1.32.3 as whenever a CSRF check fails, a callback function is called displaying a "Try again" button, which allows resending the failed request, making the CSRF attack successful.
CVE-2019-7345
- EPSS 0.67%
- Veröffentlicht 04.02.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 04:48:03
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the view 'options' (options.php) does no input validation for the WEB_TITLE, HOME_URL, HOME_CONTENT, or WEB_CONSOLE_BANNER value, allowing an attacker to execute HTML or...
CVE-2019-7344
- EPSS 0.87%
- Veröffentlicht 04.02.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 04:48:03
Reflected XSS exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in the view 'filter' as it insecurely prints the 'filter[Name]' (aka Filter name) value on the web page without applying any proper filtration.
CVE-2019-7342
- EPSS 0.99%
- Veröffentlicht 04.02.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 04:48:03
POST - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'filter[AutoExecuteCmd]' parameter value in the view filter (filter.php) because proper filtration is omit...
CVE-2019-7341
- EPSS 0.87%
- Veröffentlicht 04.02.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 04:48:03
Reflected - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'newMonitor[LinkedMonitors]' parameter value in the view monitor (monitor.php) because proper filtrat...
CVE-2019-7340
- EPSS 0.87%
- Veröffentlicht 04.02.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 04:48:03
POST - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'filter[Query][terms][0][val]' parameter value in the view filter (filter.php) because proper filtration i...
CVE-2019-7333
- EPSS 0.87%
- Veröffentlicht 04.02.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:48:02
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'Exportfile' parameter value in the view download (download.php) because proper filtration is omitted.
CVE-2019-7325
- EPSS 0.9%
- Veröffentlicht 04.02.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:48:00
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as multiple views under web/skins/classic/views insecurely utilize $_REQUEST['PHP_SELF'], without applying any proper filtration.
CVE-2019-7326
- EPSS 0.9%
- Veröffentlicht 04.02.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:48:01
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'Host' parameter value in the view console (console.php) because proper filtration is omitted. This...