Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-7325

Опубликовано: 04 фев. 2019
Источник: debian

Описание

Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as multiple views under web/skins/classic/views insecurely utilize $_REQUEST['PHP_SELF'], without applying any proper filtration.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zoneminderfixed1.34.6-1package

Примечания

  • https://github.com/ZoneMinder/zoneminder/issues/2450

  • https://github.com/ZoneMinder/zoneminder/commit/99f1e23c5b115b46265ab78d57fd6548490c6802

  • See README.Debian.security, only supported behind an authenticated HTTP zone

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 7 лет назад

Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as multiple views under web/skins/classic/views insecurely utilize $_REQUEST['PHP_SELF'], without applying any proper filtration.

CVSS3: 6.1
nvd
около 7 лет назад

Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as multiple views under web/skins/classic/views insecurely utilize $_REQUEST['PHP_SELF'], without applying any proper filtration.

CVSS3: 6.1
github
больше 3 лет назад

Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as multiple views under web/skins/classic/views insecurely utilize $_REQUEST['PHP_SELF'], without applying any proper filtration.