Show filters
83 Total Results
Displaying 71-80 of 83
Sort by:
Attacker Value
Unknown

CVE-2017-5368

Disclosure Date: February 06, 2017 (last updated November 26, 2024)
ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forgery) which allows a remote attack to make changes to the web application as the current logged in victim. If the victim visits a malicious web page, the attacker can silently and automatically create a new admin user within the web application for remote persistence and further attacks. The URL is /zm/index.php and sample parameters could include action=user uid=0 newUser[Username]=attacker1 newUser[Password]=Password1234 conf_password=Password1234 newUser[System]=Edit (among others).
0
Attacker Value
Unknown

CVE-2017-5595

Disclosure Date: February 06, 2017 (last updated November 26, 2024)
A file disclosure and inclusion vulnerability exists in web/views/file.php in ZoneMinder 1.x through v1.30.0 because of unfiltered user-input being passed to readfile(), which allows an authenticated attacker to read local system files (e.g., /etc/passwd) in the context of the web server user (www-data). The attack vector is a .. (dot dot) in the path parameter within a zm/index.php?view=file&path= request.
0
Attacker Value
Unknown

CVE-2017-5367

Disclosure Date: February 06, 2017 (last updated November 26, 2024)
Multiple reflected XSS vulnerabilities exist within form and link input parameters of ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, which allows a remote attacker to execute malicious scripts within an authenticated client's browser. The URL is /zm/index.php and sample parameters could include action=login&view=postlogin[XSS] view=console[XSS] view=groups[XSS] view=events&filter[terms][1][cnj]=and[XSS] view=events&filter%5Bterms%5D%5B1%5D%5Bcnj%5D=and[XSS] view=events&filter%5Bterms%5D%5B1%5D%5Bcnj%5D=[XSS]and view=events&limit=1%22%3E%3C/a%3E[XSS] (among others).
0
Attacker Value
Unknown

CVE-2016-10140

Disclosure Date: January 13, 2017 (last updated November 25, 2024)
Information disclosure and authentication bypass vulnerability exists in the Apache HTTP Server configuration bundled with ZoneMinder v1.30 and v1.29, which allows a remote unauthenticated attacker to browse all directories in the web root, e.g., a remote unauthenticated attacker can view all CCTV images on the server via the /events URI.
0
Attacker Value
Unknown

CVE-2013-0332

Disclosure Date: March 20, 2013 (last updated October 05, 2023)
Multiple directory traversal vulnerabilities in ZoneMinder 1.24.x before 1.24.4 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) view, (2) request, or (3) action parameter.
0
Attacker Value
Unknown

CVE-2013-0232

Disclosure Date: March 20, 2013 (last updated October 05, 2023)
includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) runState parameter in the packageControl function; or (2) key or (3) command parameter in the setDeviceStatusX10 function.
0
Attacker Value
Unknown

CVE-2008-6756

Disclosure Date: April 27, 2009 (last updated October 04, 2023)
ZoneMinder 1.23.3 on Gentoo Linux uses 0644 permissions for /etc/zm.conf, which allows local users to obtain the database username and password by reading this file.
0
Attacker Value
Unknown

CVE-2008-6755

Disclosure Date: April 27, 2009 (last updated October 04, 2023)
ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to the apache user account, and sets the permissions to 0600, which makes it easier for remote attackers to modify this file by accessing it through a (1) PHP or (2) CGI script.
0
Attacker Value
Unknown

CVE-2008-3881

Disclosure Date: September 02, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in ZoneMinder 1.23.3 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified "zm_html_view_*.php" files.
0
Attacker Value
Unknown

CVE-2008-3880

Disclosure Date: September 02, 2008 (last updated October 04, 2023)
SQL injection vulnerability in zm_html_view_event.php in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary SQL commands via the filter array parameter.
0