漏洞描述 ZoneMinder是一款免费的开源闭路电视软件应用程序,支持IP、USB和模拟摄像机等。受影响版本中,/zm/index.php中的sort参数存在SQL注入漏洞,攻击者可通过构造包含恶意sort参数的请求获取服务器敏感信息。该漏洞允许基于时间的SQL注入攻击,可能导致敏感数据泄露或其他恶意操作。
相关漏洞推荐 POC CVE-2023-26035: ZoneMinder Snapshots - Command Injection POC CVE-2024-43360: ZoneMinder - SQL Injection POC CVE-2024-51482: ZoneMinder v1.37.* <= 1.37.64 - SQL Injection POC cloudtrail-integrated-cloudwatch: CloudTrail CloudWatch Integration POC azure-network-watcher: Azure Network Watcher Service Not Enabled POC watchguard-credentials-disclosure: WatchGuard Fireware AD Helper Component - Credentials Disclosure POC digital-watchdog-default-login: Digital Watchdog - Default Login POC pgwatch2-db-exposure: Pgwatch2 DBs to monitor - Exposure POC watchguard-credentials-disclosure: WatchGuard Fireware AD Helper Component - Credentials Disclosure POC clockwatch-enterprise-rce: ClockWatch Enterprise - Remote Code Execution ZoneMinder index.php SQL注入漏洞(CVE-2024-43360) ZoneMinder ZoneMinder 需授权 SQL注入漏洞 ZoneMinder SQL注入漏洞