CVE Vulnerabilities

CVE-2013-0232

Published: Mar 20, 2013 | Modified: Aug 29, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) runState parameter in the packageControl function; or (2) key or (3) command parameter in the setDeviceStatusX10 function.

Affected Software

Name Vendor Start Version End Version
Zoneminder Zoneminder 1.24.0 (including) 1.24.0 (including)
Zoneminder Zoneminder 1.24.1 (including) 1.24.1 (including)
Zoneminder Zoneminder 1.24.2 (including) 1.24.2 (including)
Zoneminder Zoneminder 1.24.3 (including) 1.24.3 (including)
Zoneminder Zoneminder 1.24.4 (including) 1.24.4 (including)
Zoneminder Zoneminder 1.25.0 (including) 1.25.0 (including)
Zoneminder Ubuntu artful *
Zoneminder Ubuntu hardy *
Zoneminder Ubuntu lucid *
Zoneminder Ubuntu oneiric *
Zoneminder Ubuntu precise *
Zoneminder Ubuntu quantal *
Zoneminder Ubuntu raring *
Zoneminder Ubuntu saucy *
Zoneminder Ubuntu upstream *
Zoneminder Ubuntu utopic *
Zoneminder Ubuntu vivid *
Zoneminder Ubuntu wily *
Zoneminder Ubuntu yakkety *
Zoneminder Ubuntu zesty *

References