CVE-2017-5595 -- zoneminderID: oval:org.secpod.oval:def:1900348 | Date: (C)2019-02-27 (M)2023-12-20 |
Class: VULNERABILITY | Family: unix |
A file disclosure and inclusion vulnerability exists in web/views/file.php in ZoneMinder 1.x through v1.30.0 because of unfiltered user-input being passed to readfile, which allows an authenticated attacker to read local system files in the context of the web server user. The attack vector is a .. in the path parameter within a zm/index.php?view=file&path= request.
Platform: |
Ubuntu 16.04 |
Ubuntu 14.04 |