Security Advisory

CVE-2016-10140

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-01-13 09:00:00
Last updated 2024-08-06 03:14:41
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Information disclosure and authentication bypass vulnerability exists in the Apache HTTP Server configuration bundled with ZoneMinder v1.30 and v1.29, which allows a remote unauthenticated attacker to browse all directories in the web root, e.g., a remote unauthenticated attacker can view all CCTV images on the server via the /events URI.