Show filters
83 Total Results
Displaying 21-30 of 83
Sort by:
Attacker Value
Unknown
CVE-2020-25729
Disclosure Date: September 17, 2020 (last updated February 22, 2025)
ZoneMinder before 1.34.21 has XSS via the connkey parameter to download.php or export.php.
0
Attacker Value
Unknown
CVE-2019-13072
Disclosure Date: June 30, 2019 (last updated November 27, 2024)
Stored XSS in the Filters page (Name field) in ZoneMinder 1.32.3 allows a malicious user to embed and execute JavaScript code in the browser of any user who navigates to this page.
0
Attacker Value
Unknown
CVE-2019-8423
Disclosure Date: February 18, 2019 (last updated November 27, 2024)
ZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter.
0
Attacker Value
Unknown
CVE-2019-8427
Disclosure Date: February 18, 2019 (last updated November 27, 2024)
daemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters.
0
Attacker Value
Unknown
CVE-2019-8429
Disclosure Date: February 18, 2019 (last updated November 27, 2024)
ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php filter[Query][terms][0][cnj] parameter.
0
Attacker Value
Unknown
CVE-2019-8428
Disclosure Date: February 18, 2019 (last updated November 27, 2024)
ZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a newGroup[MonitorIds][] value.
0
Attacker Value
Unknown
CVE-2019-8426
Disclosure Date: February 18, 2019 (last updated November 27, 2024)
skins/classic/views/controlcap.php in ZoneMinder before 1.32.3 has XSS via the newControl array, as demonstrated by the newControl[MinTiltRange] parameter.
0
Attacker Value
Unknown
CVE-2019-8425
Disclosure Date: February 18, 2019 (last updated November 27, 2024)
includes/database.php in ZoneMinder before 1.32.3 has XSS in the construction of SQL-ERR messages.
0
Attacker Value
Unknown
CVE-2019-8424
Disclosure Date: February 18, 2019 (last updated November 27, 2024)
ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.
0
Attacker Value
Unknown
CVE-2019-7330
Disclosure Date: February 04, 2019 (last updated November 27, 2024)
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'show' parameter value in the view frame (frame.php) because proper filtration is omitted.
0