ZoneMinder before 1.23.3 allows remote authenticated users, and possibly unauthenticated attackers in some installations, to execute arbitrary commands via shell metacharacters in a crafted URL.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Zoneminder | Zoneminder | 0.0.1 (including) | 0.0.1 (including) |
Zoneminder | Zoneminder | 0.9.7 (including) | 0.9.7 (including) |
Zoneminder | Zoneminder | 0.9.8 (including) | 0.9.8 (including) |
Zoneminder | Zoneminder | 0.9.9 (including) | 0.9.9 (including) |
Zoneminder | Zoneminder | 0.9.10 (including) | 0.9.10 (including) |
Zoneminder | Zoneminder | 0.9.11 (including) | 0.9.11 (including) |
Zoneminder | Zoneminder | 0.9.12 (including) | 0.9.12 (including) |
Zoneminder | Zoneminder | 0.9.13 (including) | 0.9.13 (including) |
Zoneminder | Zoneminder | 0.9.14 (including) | 0.9.14 (including) |
Zoneminder | Zoneminder | 0.9.15 (including) | 0.9.15 (including) |
Zoneminder | Zoneminder | 0.9.16 (including) | 0.9.16 (including) |
Zoneminder | Zoneminder | 1.17.0 (including) | 1.17.0 (including) |
Zoneminder | Zoneminder | 1.17.1 (including) | 1.17.1 (including) |
Zoneminder | Zoneminder | 1.17.2 (including) | 1.17.2 (including) |
Zoneminder | Zoneminder | 1.18.0 (including) | 1.18.0 (including) |
Zoneminder | Zoneminder | 1.18.1 (including) | 1.18.1 (including) |
Zoneminder | Zoneminder | 1.19.0 (including) | 1.19.0 (including) |
Zoneminder | Zoneminder | 1.19.1 (including) | 1.19.1 (including) |
Zoneminder | Zoneminder | 1.19.2 (including) | 1.19.2 (including) |
Zoneminder | Zoneminder | 1.19.3 (including) | 1.19.3 (including) |
Zoneminder | Zoneminder | 1.19.4 (including) | 1.19.4 (including) |
Zoneminder | Zoneminder | 1.19.5 (including) | 1.19.5 (including) |
Zoneminder | Zoneminder | 1.20.0 (including) | 1.20.0 (including) |
Zoneminder | Zoneminder | 1.20.1 (including) | 1.20.1 (including) |
Zoneminder | Zoneminder | 1.21.0 (including) | 1.21.0 (including) |
Zoneminder | Zoneminder | 1.21.1 (including) | 1.21.1 (including) |
Zoneminder | Zoneminder | 1.21.2 (including) | 1.21.2 (including) |
Zoneminder | Zoneminder | 1.21.3 (including) | 1.21.3 (including) |
Zoneminder | Zoneminder | 1.21.4 (including) | 1.21.4 (including) |
Zoneminder | Zoneminder | 1.22.0 (including) | 1.22.0 (including) |
Zoneminder | Zoneminder | 1.22.1 (including) | 1.22.1 (including) |
Zoneminder | Zoneminder | 1.22.2 (including) | 1.22.2 (including) |
Zoneminder | Zoneminder | 1.22.3 (including) | 1.22.3 (including) |
Zoneminder | Zoneminder | 1.23.0 (including) | 1.23.0 (including) |
Zoneminder | Zoneminder | 1.23.1 (including) | 1.23.1 (including) |
Zoneminder | Zoneminder | 1.23.2 (including) | 1.23.2 (including) |
Zoneminder | Ubuntu | gutsy | * |
Zoneminder | Ubuntu | hardy | * |
Zoneminder | Ubuntu | upstream | * |