Beveiligingsadvies

CVE-2016-10140

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2017-01-13 09:00:00
Laatst bijgewerkt 2024-08-06 03:14:41
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

Information disclosure and authentication bypass vulnerability exists in the Apache HTTP Server configuration bundled with ZoneMinder v1.30 and v1.29, which allows a remote unauthenticated attacker to browse all directories in the web root, e.g., a remote unauthenticated attacker can view all CCTV images on the server via the /events URI.