Vulnerabilities > Zoneminder

DATE CVE VULNERABILITY TITLE RISK
2019-02-04 CVE-2019-7326 Cross-site Scripting vulnerability in Zoneminder
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'Host' parameter value in the view console (console.php) because proper filtration is omitted.
network
zoneminder CWE-79
4.3
2019-02-04 CVE-2019-7325 Cross-site Scripting vulnerability in Zoneminder
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as multiple views under web/skins/classic/views insecurely utilize $_REQUEST['PHP_SELF'], without applying any proper filtration.
network
zoneminder CWE-79
4.3
2019-01-28 CVE-2019-6992 Cross-site Scripting vulnerability in Zoneminder
A stored-self XSS exists in web/skins/classic/views/controlcaps.php of ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in a vulnerable field via a long NAME or PROTOCOL to the index.php?view=controlcaps URI.
network
zoneminder CWE-79
4.3
2019-01-28 CVE-2019-6991 Out-of-bounds Write vulnerability in Zoneminder
A classic Stack-based buffer overflow exists in the zmLoadUser() function in zm_user.cpp of the zmu binary in ZoneMinder through 1.32.3, allowing an unauthenticated attacker to execute code via a long username.
network
low complexity
zoneminder CWE-787
7.5
2019-01-28 CVE-2019-6990 Cross-site Scripting vulnerability in Zoneminder
A stored-self XSS exists in web/skins/classic/views/zones.php of ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in a vulnerable field via a crafted Zone NAME to the index.php?view=zones&action=zoneImage&mid=1 URI.
network
zoneminder CWE-79
3.5
2019-01-24 CVE-2019-6777 Cross-site Scripting vulnerability in Zoneminder 1.32.3
An issue was discovered in ZoneMinder v1.32.3.
network
zoneminder CWE-79
4.3
2018-12-20 CVE-2018-1000833 Deserialization of Untrusted Data vulnerability in Zoneminder
ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution.
network
low complexity
zoneminder CWE-502
7.5
2018-12-20 CVE-2018-1000832 Deserialization of Untrusted Data vulnerability in Zoneminder
ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution.
network
low complexity
zoneminder CWE-502
critical
10.0
2017-03-21 CVE-2017-7203 Cross-site Scripting vulnerability in Zoneminder 1.30.2
A Cross-Site Scripting (XSS) was discovered in ZoneMinder before 1.30.2.
network
zoneminder CWE-79
4.3
2017-03-03 CVE-2016-10206 Cross-Site Request Forgery (CSRF) vulnerability in Zoneminder
Cross-site request forgery (CSRF) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack the authentication of users for requests that change passwords and possibly have unspecified other impact as demonstrated by a crafted user action request to index.php.
6.8