Show filters
82 Total Results
Displaying 51-60 of 82
Sort by:
Attacker Value
Unknown

CVE-2019-7328

Disclosure Date: February 04, 2019 (last updated November 27, 2024)
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'scale' parameter value in the view frame (frame.php) via /js/frame.js.php because proper filtration is omitted.
0
Attacker Value
Unknown

CVE-2019-7339

Disclosure Date: February 04, 2019 (last updated November 27, 2024)
POST - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'level' parameter value in the view log (log.php) because proper filtration is omitted.
0
Attacker Value
Unknown

CVE-2019-7325

Disclosure Date: February 04, 2019 (last updated November 27, 2024)
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as multiple views under web/skins/classic/views insecurely utilize $_REQUEST['PHP_SELF'], without applying any proper filtration.
0
Attacker Value
Unknown

CVE-2019-7352

Disclosure Date: February 04, 2019 (last updated November 27, 2024)
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the view 'state' (aka Run State) (state.php) does no input validation to the value supplied to the 'New State' (aka newState) field, allowing an attacker to execute HTML or JavaScript code.
0
Attacker Value
Unknown

CVE-2019-7327

Disclosure Date: February 04, 2019 (last updated November 27, 2024)
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'scale' parameter value in the view frame (frame.php) because proper filtration is omitted.
0
Attacker Value
Unknown

CVE-2019-7335

Disclosure Date: February 04, 2019 (last updated November 27, 2024)
Self - Stored XSS exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in the view 'log' as it insecurely prints the 'Log Message' value on the web page without applying any proper filtration. This relates to the view=logs value.
0
Attacker Value
Unknown

CVE-2019-7340

Disclosure Date: February 04, 2019 (last updated November 27, 2024)
POST - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'filter[Query][terms][0][val]' parameter value in the view filter (filter.php) because proper filtration is omitted.
0
Attacker Value
Unknown

CVE-2019-6990

Disclosure Date: January 28, 2019 (last updated November 27, 2024)
A stored-self XSS exists in web/skins/classic/views/zones.php of ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in a vulnerable field via a crafted Zone NAME to the index.php?view=zones&action=zoneImage&mid=1 URI.
0
Attacker Value
Unknown

CVE-2019-6991

Disclosure Date: January 28, 2019 (last updated November 27, 2024)
A classic Stack-based buffer overflow exists in the zmLoadUser() function in zm_user.cpp of the zmu binary in ZoneMinder through 1.32.3, allowing an unauthenticated attacker to execute code via a long username.
0
Attacker Value
Unknown

CVE-2019-6992

Disclosure Date: January 28, 2019 (last updated November 27, 2024)
A stored-self XSS exists in web/skins/classic/views/controlcaps.php of ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in a vulnerable field via a long NAME or PROTOCOL to the index.php?view=controlcaps URI.
0