Show filters
83 Total Results
Displaying 51-60 of 83
Sort by:
Attacker Value
Unknown
CVE-2019-7328
Disclosure Date: February 04, 2019 (last updated November 27, 2024)
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'scale' parameter value in the view frame (frame.php) via /js/frame.js.php because proper filtration is omitted.
0
Attacker Value
Unknown
CVE-2019-7339
Disclosure Date: February 04, 2019 (last updated November 27, 2024)
POST - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'level' parameter value in the view log (log.php) because proper filtration is omitted.
0
Attacker Value
Unknown
CVE-2019-7325
Disclosure Date: February 04, 2019 (last updated November 27, 2024)
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as multiple views under web/skins/classic/views insecurely utilize $_REQUEST['PHP_SELF'], without applying any proper filtration.
0
Attacker Value
Unknown
CVE-2019-7352
Disclosure Date: February 04, 2019 (last updated November 27, 2024)
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the view 'state' (aka Run State) (state.php) does no input validation to the value supplied to the 'New State' (aka newState) field, allowing an attacker to execute HTML or JavaScript code.
0
Attacker Value
Unknown
CVE-2019-7327
Disclosure Date: February 04, 2019 (last updated November 27, 2024)
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'scale' parameter value in the view frame (frame.php) because proper filtration is omitted.
0
Attacker Value
Unknown
CVE-2019-7335
Disclosure Date: February 04, 2019 (last updated November 27, 2024)
Self - Stored XSS exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in the view 'log' as it insecurely prints the 'Log Message' value on the web page without applying any proper filtration. This relates to the view=logs value.
0
Attacker Value
Unknown
CVE-2019-7340
Disclosure Date: February 04, 2019 (last updated November 27, 2024)
POST - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'filter[Query][terms][0][val]' parameter value in the view filter (filter.php) because proper filtration is omitted.
0
Attacker Value
Unknown
CVE-2019-6990
Disclosure Date: January 28, 2019 (last updated November 27, 2024)
A stored-self XSS exists in web/skins/classic/views/zones.php of ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in a vulnerable field via a crafted Zone NAME to the index.php?view=zones&action=zoneImage&mid=1 URI.
0
Attacker Value
Unknown
CVE-2019-6991
Disclosure Date: January 28, 2019 (last updated November 27, 2024)
A classic Stack-based buffer overflow exists in the zmLoadUser() function in zm_user.cpp of the zmu binary in ZoneMinder through 1.32.3, allowing an unauthenticated attacker to execute code via a long username.
0
Attacker Value
Unknown
CVE-2019-6992
Disclosure Date: January 28, 2019 (last updated November 27, 2024)
A stored-self XSS exists in web/skins/classic/views/controlcaps.php of ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in a vulnerable field via a long NAME or PROTOCOL to the index.php?view=controlcaps URI.
0