Show filters
82 Total Results
Displaying 21-30 of 82
Sort by:
Attacker Value
Unknown

CVE-2020-25729

Disclosure Date: September 17, 2020 (last updated February 22, 2025)
ZoneMinder before 1.34.21 has XSS via the connkey parameter to download.php or export.php.
Attacker Value
Unknown

CVE-2019-13072

Disclosure Date: June 30, 2019 (last updated November 27, 2024)
Stored XSS in the Filters page (Name field) in ZoneMinder 1.32.3 allows a malicious user to embed and execute JavaScript code in the browser of any user who navigates to this page.
Attacker Value
Unknown

CVE-2019-8423

Disclosure Date: February 18, 2019 (last updated November 27, 2024)
ZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter.
0
Attacker Value
Unknown

CVE-2019-8427

Disclosure Date: February 18, 2019 (last updated November 27, 2024)
daemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters.
0
Attacker Value
Unknown

CVE-2019-8429

Disclosure Date: February 18, 2019 (last updated November 27, 2024)
ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php filter[Query][terms][0][cnj] parameter.
0
Attacker Value
Unknown

CVE-2019-8428

Disclosure Date: February 18, 2019 (last updated November 27, 2024)
ZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a newGroup[MonitorIds][] value.
0
Attacker Value
Unknown

CVE-2019-8426

Disclosure Date: February 18, 2019 (last updated November 27, 2024)
skins/classic/views/controlcap.php in ZoneMinder before 1.32.3 has XSS via the newControl array, as demonstrated by the newControl[MinTiltRange] parameter.
0
Attacker Value
Unknown

CVE-2019-8425

Disclosure Date: February 18, 2019 (last updated November 27, 2024)
includes/database.php in ZoneMinder before 1.32.3 has XSS in the construction of SQL-ERR messages.
0
Attacker Value
Unknown

CVE-2019-8424

Disclosure Date: February 18, 2019 (last updated November 27, 2024)
ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.
0
Attacker Value
Unknown

CVE-2019-7330

Disclosure Date: February 04, 2019 (last updated November 27, 2024)
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'show' parameter value in the view frame (frame.php) because proper filtration is omitted.
0