CVE-2013-0232

high
Published 2013-03-20 · Modified 2026-04-29
CVSS v3
VIR risk
7.5

Description

includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) runState parameter in the packageControl function; or (2) key or (3) command parameter in the setDeviceStatusX10 function.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1.25.0-4
debian debianbullseyefixed1.25.0-4
debian debianforkyfixed1.25.0-4
debian debiansidfixed1.25.0-4
debian debiantrixiefixed1.25.0-4

Application impact

VendorProductVersionsFixed
zoneminderzoneminder1.24.0
zoneminderzoneminder1.24.1
zoneminderzoneminder1.24.2
zoneminderzoneminder1.24.3
zoneminderzoneminder1.24.4
zoneminderzoneminder1.25.0

References

💬 Discuss CVE-2013-0232 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.