Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-26037

Опубликовано: 25 фев. 2023
Источник: debian
EPSS Низкий

Описание

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain an SQL Injection. The minTime and maxTime request parameters are not properly validated and could be used execute arbitrary SQL. This issue is fixed in versions 1.36.33 and 1.37.33.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zoneminderfixed1.36.33+dfsg1-1package

Примечания

  • Only supported for trusted users/behind auth

  • https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-65jp-2hj3-3733

  • https://github.com/ZoneMinder/zoneminder/commit/4f4ddaab3f982890750594c471bd6b8f72d05dbd

EPSS

Процентиль: 40%
0.00179
Низкий

Связанные уязвимости

CVSS3: 8.9
ubuntu
почти 3 года назад

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain an SQL Injection. The minTime and maxTime request parameters are not properly validated and could be used execute arbitrary SQL. This issue is fixed in versions 1.36.33 and 1.37.33.

CVSS3: 8.9
nvd
почти 3 года назад

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain an SQL Injection. The minTime and maxTime request parameters are not properly validated and could be used execute arbitrary SQL. This issue is fixed in versions 1.36.33 and 1.37.33.

EPSS

Процентиль: 40%
0.00179
Низкий