Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8937-h2h2-h5rj

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Log Injection exists in ZoneMinder through 1.32.3, as an attacker can entice the victim to visit a specially crafted link, which in turn will inject a custom Log message provided by the attacker in the 'log' view page, as demonstrated by the message=User%20'admin'%20Logged%20in value.

Log Injection exists in ZoneMinder through 1.32.3, as an attacker can entice the victim to visit a specially crafted link, which in turn will inject a custom Log message provided by the attacker in the 'log' view page, as demonstrated by the message=User%20'admin'%20Logged%20in value.

EPSS

Процентиль: 48%
0.00252
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 7 лет назад

Log Injection exists in ZoneMinder through 1.32.3, as an attacker can entice the victim to visit a specially crafted link, which in turn will inject a custom Log message provided by the attacker in the 'log' view page, as demonstrated by the message=User%20'admin'%20Logged%20in value.

CVSS3: 6.5
nvd
около 7 лет назад

Log Injection exists in ZoneMinder through 1.32.3, as an attacker can entice the victim to visit a specially crafted link, which in turn will inject a custom Log message provided by the attacker in the 'log' view page, as demonstrated by the message=User%20'admin'%20Logged%20in value.

CVSS3: 6.5
debian
около 7 лет назад

Log Injection exists in ZoneMinder through 1.32.3, as an attacker can ...

EPSS

Процентиль: 48%
0.00252
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-74