PT-2013-2175 · Zoneminder · Zoneminder Video Server

Published

2013-03-20

·

Updated

2013-08-29

·

CVE-2013-0232

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ZoneMinder Video Server versions 1.24.0 and earlier ZoneMinder Video Server version 1.25.0
Description The issue allows remote attackers to execute arbitrary commands. This can be achieved via shell metacharacters in the runState parameter in the packageControl function, or the key or command parameter in the setDeviceStatusX10 function.
Recommendations For ZoneMinder Video Server versions 1.24.0 and earlier, and version 1.25.0, consider disabling the packageControl and setDeviceStatusX10 functions until a patch is available to prevent exploitation. Restrict access to the includes/functions.php file to minimize the risk of arbitrary command execution. Avoid using the runState, key, and command parameters in the affected functions until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2013-0232
DSA-2640-1

Affected Products

Zoneminder Video Server