Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-31493

Опубликовано: 15 окт. 2024
Источник: debian
EPSS Низкий

Описание

RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a crafted payload and escalate privileges allowing execution of any commands on the remote system.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zoneminderunfixedpackage

Примечания

  • Only supported for trusted users/behind auth

  • https://medium.com/@dk50u1/rce-remote-code-execution-in-zoneminder-up-to-1-36-33-0686f5bcd370

EPSS

Процентиль: 77%
0.01057
Низкий

Связанные уязвимости

CVSS3: 6.6
ubuntu
больше 1 года назад

RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a crafted payload and escalate privileges allowing execution of any commands on the remote system.

CVSS3: 6.6
nvd
больше 1 года назад

RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a crafted payload and escalate privileges allowing execution of any commands on the remote system.

EPSS

Процентиль: 77%
0.01057
Низкий