CVE-2016-10140
ZoneMinder XSS / CSRF / File Disclosure / Authentication Bypass
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Information disclosure and authentication bypass vulnerability exists in the Apache HTTP Server configuration bundled with ZoneMinder v1.30 and v1.29, which allows a remote unauthenticated attacker to browse all directories in the web root, e.g., a remote unauthenticated attacker can view all CCTV images on the server via the /events URI.
La vulnerabilidad de desvío de autenticación y divulgación de información existe en la configuración del servidor HTTP de Apache incluida con ZoneMinder v1.30 y v1.29, que permite a un atacante remoto no autenticado explorar todos los directorios de la raíz web, por ejemplo, un atacante remoto no autenticado puede ver todas las imágenes CCTV en el servidor a través de la URI /events.
Various ZoneMinder versions suffer from authentication bypass, cross site request forgery, cross site scripting, information disclosure, and file disclosure vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-01-13 CVE Reserved
- 2017-01-13 CVE Published
- 2021-12-23 First Exploit
- 2024-08-06 CVE Updated
- 2024-08-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://seclists.org/bugtraq/2017/Feb/6 | X_refsource_misc | |
http://seclists.org/fulldisclosure/2017/Feb/11 | X_refsource_misc | |
http://www.securityfocus.com/bid/96849 | Vdb Entry | |
https://github.com/ZoneMinder/ZoneMinder/commit/71898df7565ed2a51dfe76a1cf30ddb81fc888ba | X_refsource_confirm | |
https://github.com/ZoneMinder/ZoneMinder/pull/1697 | Issue Tracking |
URL | Date | SRC |
---|---|---|
https://github.com/asaotomo/CVE-2016-10140-Zoneminder-Poc | 2021-12-23 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zoneminder Search vendor "Zoneminder" | Zoneminder Search vendor "Zoneminder" for product "Zoneminder" | 1.30.0 Search vendor "Zoneminder" for product "Zoneminder" and version "1.30.0" | - |
Affected
|