Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) runState parameter in the packageControl function; or (2) key or (3) command parameter in the setDeviceStatusX10 function.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ZoneMinder Video Server 远程多个任意命令执行漏洞
Vulnerability Description
ZoneMinder Video Server 1.24.0,1.25.0和较早版本中的includes/functions.php脚本中存在漏洞。通过packageControl函数中的(1)runState参数,或setDeviceStatusX10函数中的(2)key或(3)command参数中的shell元字符,远程攻击者利用该漏洞执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A