Lucene search

K
nvd[email protected]NVD:CVE-2013-0232
HistoryMar 20, 2013 - 3:55 p.m.

CVE-2013-0232

2013-03-2015:55:00
web.nvd.nist.gov
8

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.6

Confidence

Low

EPSS

0.648

Percentile

97.9%

includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) runState parameter in the packageControl function; or (2) key or (3) command parameter in the setDeviceStatusX10 function.

Affected configurations

Nvd
Node
zoneminderzoneminderMatch1.24.0
OR
zoneminderzoneminderMatch1.24.1
OR
zoneminderzoneminderMatch1.24.2
OR
zoneminderzoneminderMatch1.24.3
OR
zoneminderzoneminderMatch1.24.4
OR
zoneminderzoneminderMatch1.25.0
VendorProductVersionCPE
zoneminderzoneminder1.24.0cpe:2.3:a:zoneminder:zoneminder:1.24.0:*:*:*:*:*:*:*
zoneminderzoneminder1.24.1cpe:2.3:a:zoneminder:zoneminder:1.24.1:*:*:*:*:*:*:*
zoneminderzoneminder1.24.2cpe:2.3:a:zoneminder:zoneminder:1.24.2:*:*:*:*:*:*:*
zoneminderzoneminder1.24.3cpe:2.3:a:zoneminder:zoneminder:1.24.3:*:*:*:*:*:*:*
zoneminderzoneminder1.24.4cpe:2.3:a:zoneminder:zoneminder:1.24.4:*:*:*:*:*:*:*
zoneminderzoneminder1.25.0cpe:2.3:a:zoneminder:zoneminder:1.25.0:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.6

Confidence

Low

EPSS

0.648

Percentile

97.9%