CVE-2013-0232

ZoneMinder Video Server <1.25.0 - Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2013-0232. PoCs published by Metasploit, bcoles, including Metasploit module exploits/unix/webapp/zoneminder_packagecontrol_exec.

AI-analyzed exploit summary This Metasploit module exploits a command execution vulnerability in ZoneMinder Video Server versions 1.24.0 to 1.25.0 by injecting arbitrary commands via the 'runState' parameter in the 'packageControl' function.

Description

includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) runState parameter in the packageControl function; or (2) key or (3) command parameter in the setDeviceStatusX10 function.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremoteunix
https://www.exploit-db.com/exploits/24310

This Metasploit module exploits a command execution vulnerability in ZoneMinder Video Server versions 1.24.0 to 1.25.0 by injecting arbitrary commands via the 'runState' parameter in the 'packageControl' function.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: ZoneMinder Video Server 1.24.0 to 1.25.0
Auth required
Prerequisites: Valid credentials for ZoneMinder · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by bcoles · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/zoneminder_packagecontrol_exec.rb

This Metasploit module exploits a command execution vulnerability in ZoneMinder Video Server versions 1.24.0 to 1.25.0 by leveraging the 'packageControl' function, which passes user-controlled input from the 'runState' parameter to the 'exec()' function.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: ZoneMinder Video Server 1.24.0 to 1.25.0
Auth required
Prerequisites: Valid ZoneMinder credentials · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2013/dsa-2640
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/24310
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/89529
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2013/01/28/2

Scores

EPSS 0.4789
EPSS Percentile 98.7%

Details

Status published
Products (6)
zoneminder/zoneminder 1.24.0
zoneminder/zoneminder 1.24.1
zoneminder/zoneminder 1.24.2
zoneminder/zoneminder 1.24.3
zoneminder/zoneminder 1.24.4
zoneminder/zoneminder 1.25.0
Published Mar 20, 2013
Tracked Since Feb 18, 2026