Zoneminder

View CSAF
Summary
Successful exploitation of this vulnerability could result in full Remote Code Execution (RCE) as the web server user.
The following versions of Zoneminder are affected:

Zoneminder 1.37.48|1.38.3 

CVSS
Vendor
Equipment
Vulnerabilities

v3 8.8
Zoneminder
Zoneminder
Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’)

Background

Critical Infrastructure Sectors: Information Technology
Countries/Areas Deployed: Worldwide
Comp…

📰 来源: CISA 安全公告

⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。
滚动至顶部