Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 as the view 'events' (events.php) insecurely displays the limit parameter value, without applying any proper output filtration. This issue exists because of the function sortHeader() in functions.php, which insecurely returns the value of the limit query string parameter without applying any filtration.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ZoneMinder 跨站脚本漏洞
Vulnerability Description
ZoneMinder是一套开源的视频监控软件系统。该系统支持IP、USB和模拟摄像机等。 ZoneMinder 1.32.3及之前版本中的functions.php文件的‘sortHeader’函数存在跨站脚本漏洞,该漏洞源于events.php文件没有进行任意的输出过滤就展示了‘limit’参数值。远程攻击者可利用该漏洞在用于浏览器中执行脚本。
CVSS Information
N/A
Vulnerability Type
N/A