5
CVSSv2

CVE-2008-6755

Published: 27/04/2009 Updated: 17/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to the apache user account, and sets the permissions to 0600, which makes it easier for remote malicious users to modify this file by accessing it through a (1) PHP or (2) CGI script.

Vulnerable Product Search on Vulmon Subscribe to Product

zoneminder zoneminder 1.23.3

Vendor Advisories

Debian Bug report logs - #528252 zoneminder: conf file permissions need to be more restrictive Package: zoneminder; Maintainer for zoneminder is Dmitry Smirnov <onlyjob@debianorg>; Source for zoneminder is src:zoneminder (PTS, buildd, popcon) Reported by: "Michael S Gilbert" <michaelsgilbert@gmailcom> Date: Mon, ...
Debian Bug report logs - #497640 zoneminder: Several security issues (XSS, SQL injection, Command injection) Package: zoneminder; Maintainer for zoneminder is Dmitry Smirnov <onlyjob@debianorg>; Source for zoneminder is src:zoneminder (PTS, buildd, popcon) Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> D ...