CVE-2013-0232

ZoneMinder Video Server <1.25.0 - Command Injection

Title source: llm

Description

includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) runState parameter in the packageControl function; or (2) key or (3) command parameter in the setDeviceStatusX10 function.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremoteunix
https://www.exploit-db.com/exploits/24310
metasploit WORKING POC EXCELLENT
by bcoles · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/zoneminder_packagecontrol_exec.rb

Scores

EPSS 0.7823
EPSS Percentile 99.0%

Classification

Status draft

Affected Products (6)

zoneminder/zoneminder
zoneminder/zoneminder
zoneminder/zoneminder
zoneminder/zoneminder
zoneminder/zoneminder
zoneminder/zoneminder

Timeline

Published Mar 20, 2013
Tracked Since Feb 18, 2026