ZoneMinder是ZoneMinder开源的一套开源的视频监控软件系统。该系统支持IP、USB和模拟摄像机等。 ZoneMinder 1.36.37及之前版本和1.37.61版本至1.38.0版本存在SQL注入漏洞,该漏洞源于web/ajax/status.php文件中getNearEvents函数存在二阶SQL注入,可能导致执行任意SQL查询。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ZoneMinder | zoneminder | < 1.36.38 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | ZoneMinder Second-Order SQL Injection PoC — CVE-2026-27470 | https://github.com/kocaemre/CVE-2026-27470 | POC Details |
No public POC found.
Login to generate AI POCNo comments yet