mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-11 20:52:49 +02:00
18 lines
834 B
Markdown
18 lines
834 B
Markdown
### [CVE-2013-0232](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0232)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) runState parameter in the packageControl function; or (2) key or (3) command parameter in the setDeviceStatusX10 function.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- http://itsecuritysolutions.org/2013-01-22-ZoneMinder-Video-Server-arbitrary-command-execution-vulnerability/
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|