ZoneMinder before 1.23.3 allows remote authenticated users, and possibly unauthenticated attackers in some installations, to execute arbitrary commands via shell metacharacters in a crafted URL. The following link contains patch information: http://www.zoneminder.com/wiki/index.php/1.23.2_Patches
Publication date: Fri, 02 May 2008 00:05:00 +0000