CVE Vulnerabilities

CVE-2013-0232

Published: Mar 20, 2013 | Modified: Aug 29, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) runState parameter in the packageControl function; or (2) key or (3) command parameter in the setDeviceStatusX10 function.

Affected Software

Name Vendor Start Version End Version
Zoneminder Zoneminder 1.24.0 (including) 1.24.0 (including)
Zoneminder Zoneminder 1.24.1 (including) 1.24.1 (including)
Zoneminder Zoneminder 1.24.2 (including) 1.24.2 (including)
Zoneminder Zoneminder 1.24.3 (including) 1.24.3 (including)
Zoneminder Zoneminder 1.24.4 (including) 1.24.4 (including)
Zoneminder Zoneminder 1.25.0 (including) 1.25.0 (including)

References