Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zoneminder zoneminder vulnerabilities and exploits
(subscribe to this query)
383
VMScore
CVE-2019-7348
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder up to and including 1.32.3, allowing an malicious user to execute HTML or JavaScript code via a vulnerable 'username' parameter value in the view user (user.php) because proper filtration is omitted.
Zoneminder Zoneminder
383
VMScore
CVE-2019-7349
Reflected Cross Site Scripting (XSS) exists in ZoneMinder up to and including 1.32.3, allowing an malicious user to execute HTML or JavaScript code via a vulnerable 'newMonitor[V4LCapturesPerFrame]' parameter value in the view monitor (monitor.php) because proper filtra...
Zoneminder Zoneminder
436
VMScore
CVE-2019-7350
Session fixation exists in ZoneMinder up to and including 1.32.3, as an attacker can fixate his own session cookies to the next logged-in user, thereby hijacking the victim's account. This occurs because a set of multiple cookies (between 3 and 5) is being generated when a u...
Zoneminder Zoneminder
383
VMScore
CVE-2019-7352
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder up to and including 1.32.3, as the view 'state' (aka Run State) (state.php) does no input validation to the value supplied to the 'New State' (aka newState) field, allowing an malicious user to exec...
Zoneminder Zoneminder
383
VMScore
CVE-2019-7328
Reflected Cross Site Scripting (XSS) exists in ZoneMinder up to and including 1.32.3, allowing an malicious user to execute HTML or JavaScript code via a vulnerable 'scale' parameter value in the view frame (frame.php) via /js/frame.js.php because proper filtration is o...
Zoneminder Zoneminder
383
VMScore
CVE-2019-7330
Reflected Cross Site Scripting (XSS) exists in ZoneMinder up to and including 1.32.3, allowing an malicious user to execute HTML or JavaScript code via a vulnerable 'show' parameter value in the view frame (frame.php) because proper filtration is omitted.
Zoneminder Zoneminder
383
VMScore
CVE-2019-7331
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder up to and including 1.32.3 while editing an existing monitor field named "signal check color" (monitor.php). There exists no input validation or output filtration, leaving it vulnerable to HTML Injection and ...
Zoneminder Zoneminder
383
VMScore
CVE-2019-7332
Reflected Cross Site Scripting (XSS) exists in ZoneMinder up to and including 1.32.3, allowing an malicious user to execute HTML or JavaScript code via a vulnerable 'eid' (aka Event ID) parameter value in the view download (download.php) because proper filtration is omi...
Zoneminder Zoneminder
383
VMScore
CVE-2019-7335
Self - Stored XSS exists in ZoneMinder up to and including 1.32.3, allowing an malicious user to execute HTML or JavaScript code in the view 'log' as it insecurely prints the 'Log Message' value on the web page without applying any proper filtration. This rela...
Zoneminder Zoneminder
312
VMScore
CVE-2019-7337
Reflected Cross Site Scripting (XSS) exists in ZoneMinder up to and including 1.32.3 as the view 'events' (events.php) insecurely displays the limit parameter value, without applying any proper output filtration. This issue exists because of the function sortHeader() in...
Zoneminder Zoneminder
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
validation
CVE-2012-1823
malicious code
CVE-2024-5770
CVE-2023-45866
CVE-2024-35687
local users
CVE-2024-31246
CVE-2024-35730
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »