目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2023-26035 PoC — ZoneMinder 安全漏洞

来源
关联漏洞
标题: ZoneMinder 安全漏洞 (CVE-2023-26035)
Description:ZoneMinder是一套开源的视频监控软件系统。该系统支持IP、USB和模拟摄像机等。 ZoneMinder 1.36.33之前版本和1.37.33之前版本存在安全漏洞,该漏洞源于存在通过缺失授权进行未经认证的远程代码执行的漏洞。
Description
ZoneMinder Snapshots - Unauthenticated
介绍
# CVE-2023-26035
ZoneMinder Snapshots - Unauthenticated
![image](https://github.com/Yuma-Tsushima07/CVE-2023-26035/assets/63207324/c4666544-871c-496b-8b35-6011a0f36e96)
![image](https://github.com/Yuma-Tsushima07/CVE-2023-26035/assets/63207324/798ca08e-95bc-433e-8862-d9bca4560f05)

## Install
**Grab Repo**
```bash
$ git clone https://github.com/Yuma-Tsushima07/CVE-2023-26035.git
```

**Setup**
> Note: Install the latest version of `node`
```bash
$ npm init
$ npm i axios cheerio yargs
```

## Usage
```
┌─[✗]─[v37r1x@7h3B14ckKn1gh75]─[~/Documents/Code/CVE-2023-26035]
└──╼ $node exp.js -h
Options:
      --version  Show version number                                   [boolean]
  -t, --target   Target URI (e.g., http://example.com/zm/)   [string] [required]
  -c, --cmd      Command to execute on the target            [string] [required]
  -h, --help     Show help                                             [boolean]
```
```
┌─[v37r1x@7h3B14ckKn1gh75]─[~/Documents/Code/CVE-2023-26035]
└──╼ $node exp.js -t http://127.0.0.1:8888/ --cmd '<shell>'
```

## Credits

- [rvizx](https://github.com/rvizx/CVE-2023-26035)
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →