Back to search
CVE-2022-29806
Published: Apr 26, 2022
Modified: Aug 3, 2024
PUBLISHED
Description
ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary pathname contributes to exploitability.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://forums.zoneminder.com/viewtopic.php?t=31638
x_refsource_MISC
https://github.com/ZoneMinder/zoneminder/releases/tag/1.36.13
x_refsource_MISC
https://krastanoel.com/cve/2022-29806
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now