NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
76463 | CVE-2000-0220 | ZoneAlarm sends sensitive system and network information in cleartext to the Zone Labs server if a user requests more information about an event. | 2 | 5 | Medium | 2017-01-05 | 2008-09-10 | View | |
6486 | CVE-2008-6755 | ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to the apache user account, and sets the permissions to 0600, which makes it easier for remote attackers to modify this file by accessing it through a (1) PHP or (2) CGI script. | 2 | 5 | Medium | 2017-01-03 | 2009-05-13 | View | |
6487 | CVE-2008-6756 | ZoneMinder 1.23.3 on Gentoo Linux uses 0644 permissions for /etc/zm.conf, which allows local users to obtain the database username and password by reading this file. | 2 | 2.1 | Low | 2017-01-03 | 2009-05-13 | View | |
1339 | CVE-2008-1381 | ZoneMinder before 1.23.3 allows remote authenticated users, and possibly unauthenticated attackers in some installations, to execute arbitrary commands via shell metacharacters in a crafted URL. | 2 | 7.5 | High | 2017-01-03 | 2008-11-26 | View | |
81631 | CVE-2017-5368 | ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forgery) which allows a remote attack to make changes to the web application as the current logged in victim. If the victim visits a malicious web page, the attacker can silently and automatically create a new admin user within the web application for remote persistence and further attacks. The URL is /zm/index.php and sample parameters could include action=user uid=0 newUser[Username]=attacker1 newUser[Password]=Password1234 conf_password=Password1234 newUser[System]=Edit (among others). | 2 | 6.8 | Medium | 2017-02-15 | 2017-02-09 | View |
Page 17659 of 17672, showing 5 records out of 88360 total, starting on record 88291, ending on 88295