CVE-2013-0232
ZoneMinder Video Server <1.25.0 - Command Injection
Title source: llmDescription
includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) runState parameter in the packageControl function; or (2) key or (3) command parameter in the setDeviceStatusX10 function.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremoteunix
https://www.exploit-db.com/exploits/24310
metasploit
WORKING POC
EXCELLENT
by bcoles · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/zoneminder_packagecontrol_exec.rb
References (7)
Scores
EPSS
0.7823
EPSS Percentile
99.0%
Classification
Status
draft
Affected Products (6)
zoneminder/zoneminder
zoneminder/zoneminder
zoneminder/zoneminder
zoneminder/zoneminder
zoneminder/zoneminder
zoneminder/zoneminder
Timeline
Published
Mar 20, 2013
Tracked Since
Feb 18, 2026