ZoneMinder是一套开源的视频监控软件系统。该系统支持IP、USB和模拟摄像机等。 ZoneMinder 1.36.26及之前版本、1.37.23及之前版本存在输入验证错误漏洞,该漏洞源于允许具有查看系统权限的用户将新数据注入到 Zoneminder 存储的日志中,攻击者利用该漏洞可能会影响数据库性能或消耗所有存储资源。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ZoneMinder | zoneminder | < 1.36.27 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-39289 | 9.1 CRITICAL | Database log access in ZoneMinder |
| CVE-2022-39290 | 8.0 HIGH | CSRF key bypass using HTTP methods in zoneminder |
| CVE-2022-39285 | 7.6 HIGH | Stored Cross-Site Scripting Vulnerability In File Parameter in zoneminder |
No comments yet