CVE-2019-8427: OS Command Injection
Published Feb 18, 2019
·Updated
daemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters.
Affected Software
1 affected component
ZoneMinder Zoneminder<1.32.3
Event History
Feb 18, 2019
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·12:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-8427.
2
What is the severity level of CVE-2019-8427?
The severity level of CVE-2019-8427 is critical (9.8).
3
What is the affected software for CVE-2019-8427?
The affected software for CVE-2019-8427 is ZoneMinder before version 1.32.3.
4
How does CVE-2019-8427 allow command injection?
CVE-2019-8427 allows command injection via shell metacharacters in the daemonControl function of includes/functions.php.
5
Is there a fix available for CVE-2019-8427?
Yes, the fix for CVE-2019-8427 is to upgrade ZoneMinder to version 1.32.3 or newer.