CVE-2013-0232: High severity zoneminder zoneminder vulnerability
includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) runState parameter in the packageControl function; or (2) key or (3) command parameter in the setDeviceStatusX10 function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0232?
CVE-2013-0232 is considered a high-severity vulnerability due to its potential for remote command execution.
How do I fix CVE-2013-0232?
To fix CVE-2013-0232, you should upgrade to the latest version of ZoneMinder that addresses this vulnerability.
What versions of ZoneMinder are affected by CVE-2013-0232?
CVE-2013-0232 affects ZoneMinder versions 1.24.0, 1.24.1, 1.24.2, 1.24.3, 1.24.4, and 1.25.0.
What are the potential exploits of CVE-2013-0232?
Attackers can exploit CVE-2013-0232 to execute arbitrary commands on the affected ZoneMinder server.
What parameters are involved in the exploitation of CVE-2013-0232?
The exploitation of CVE-2013-0232 can occur through shell metacharacters in the runState, key, or command parameters.