CVE-2024-43360
CRITICAL EXPLOITED NUCLEIZoneMinder < 1.36.34 - Time-Based SQL Injection
Title source: llmExploitation Summary
CVE-2024-43360 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including iSee857. A Nuclei detection template is also available.
AI-analyzed exploit summary The repository contains functional exploit code for CVE-2024-43360, demonstrating a command execution vulnerability in OpenCode. The script sends crafted requests to exploit the vulnerability and verify command execution via the 'id' command.
Description
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability. This vulnerability is fixed in 1.36.34 and 1.37.61.
Exploits (1)
The repository contains functional exploit code for CVE-2024-43360, demonstrating a command execution vulnerability in OpenCode. The script sends crafted requests to exploit the vulnerability and verify command execution via the 'id' command.
Nuclei Templates (1)
icon_hash="-1218152116"
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H