ZoneMinder.Snapshots.Remote.Command.Injection
Description
This indicates an attack attempt to exploit an Remote Command Injection Vulnerability in ZoneMinder.
This vulnerability is due to an error when sending a crafted HTTP request to the vulnerable server. A remote attacker could exploit this vulnerability by sending a crafted HTTP request to the target server. Successfully exploiting this vulnerability could result in remote code execution in the context of the target system.
Affected Products
ZoneMinder version 1.36.32
ZoneMinder version 1.37.00 to version 1.37.32
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-72rg-h4vf-29gr
Coverage
| IPS (Regular DB) | |
| IPS (Extended DB) |