CVE-2022-29806
CRITICALZoneMinder < 1.36.13 - Remote Code Execution via Invalid Language Setting
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2022-29806.
PoCs published by Sigm0n, krastanoel, including Metasploit module exploits/unix/webapp/zoneminder_lang_exec.
AI-analyzed exploit summary This is a functional exploit for CVE-2022-29806, targeting a path traversal vulnerability in ZoneMinder up to 1.36.12. It achieves RCE by manipulating debug log file paths and default language options to write and execute arbitrary PHP code.
Description
ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary pathname contributes to exploitability.
Exploits (2)
This is a functional exploit for CVE-2022-29806, targeting a path traversal vulnerability in ZoneMinder up to 1.36.12. It achieves RCE by manipulating debug log file paths and default language options to write and execute arbitrary PHP code.
This Metasploit module exploits a chained vulnerability in ZoneMinder (CVE-2022-29806) involving arbitrary file write via debug log manipulation and path traversal in language settings to achieve remote code execution. It authenticates, leaks the installation path, writes a PHP payload to a traversed path, and triggers execution by modifying language settings.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H