5
CVSSv2

CVE-2013-0332

Published: 20/03/2013 Updated: 21/03/2013
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 510
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Multiple directory traversal vulnerabilities in ZoneMinder 1.24.x prior to 1.24.4 allow remote malicious users to read arbitrary files via a .. (dot dot) in the (1) view, (2) request, or (3) action parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

zoneminder zoneminder 1.24.0

zoneminder zoneminder 1.24.1

zoneminder zoneminder 1.24.3

zoneminder zoneminder 1.24.2

Vendor Advisories

Debian Bug report logs - #698910 zoneminder: CVE-2013-0232: arbitrary command execution vulnerability Package: src:zoneminder; Maintainer for src:zoneminder is Dmitry Smirnov <onlyjob@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 25 Jan 2013 07:00:02 UTC Severity: grave Tags: patch, se ...
Debian Bug report logs - #700912 zoneminder: CVE-2013-0332: local file inclusion vulnerability Package: zoneminder; Maintainer for zoneminder is Dmitry Smirnov <onlyjob@debianorg>; Source for zoneminder is src:zoneminder (PTS, buildd, popcon) Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 19 Feb 20 ...

Exploits

# Exploit Title: Zoneminder 1243 Remote File Inclusion Vulnerability # Date: 2011-07-22 # Author: Iye (iye[dot]cba-at-gmail[dot]com) # Software Link: wwwzonemindercom/ # Version: 1243 (Tested) 1244 probably too, not tested # Tested on: Ubuntu 1004 You must be authenticated as a user in the Web App to exploit it It's not a must to ...
## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' class Metasploit3 < Msf::Exploit::Remote Rank = ExcellentRanking in ...