NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
76463  CVE-2000-0220  ZoneAlarm sends sensitive system and network information in cleartext to the Zone Labs server if a user requests more information about an event.    Medium  2017-01-05  2008-09-10  View
6486  CVE-2008-6755  ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to the apache user account, and sets the permissions to 0600, which makes it easier for remote attackers to modify this file by accessing it through a (1) PHP or (2) CGI script.    Medium  2017-01-03  2009-05-13  View
6487  CVE-2008-6756  ZoneMinder 1.23.3 on Gentoo Linux uses 0644 permissions for /etc/zm.conf, which allows local users to obtain the database username and password by reading this file.    2.1  Low  2017-01-03  2009-05-13  View
1339  CVE-2008-1381  ZoneMinder before 1.23.3 allows remote authenticated users, and possibly unauthenticated attackers in some installations, to execute arbitrary commands via shell metacharacters in a crafted URL.    7.5  High  2017-01-03  2008-11-26  View
81631  CVE-2017-5368  ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forgery) which allows a remote attack to make changes to the web application as the current logged in victim. If the victim visits a malicious web page, the attacker can silently and automatically create a new admin user within the web application for remote persistence and further attacks. The URL is /zm/index.php and sample parameters could include action=user uid=0 newUser[Username]=attacker1 newUser[Password]=Password1234 conf_password=Password1234 newUser[System]=Edit (among others).    6.8  Medium  2017-02-15  2017-02-09  View

Page 17659 of 17672, showing 5 records out of 88360 total, starting on record 88291, ending on 88295

Actions