I've managed to find a security hole that will give you admin access in zoneminder without a need for a password. I've emailed the zoneminder user and gave him the details, and hope the fix gets out in the next release. I'm hessitant to give any details publicly till a patch is made to fix the hole. I'm posting here in case there is soneone else I should email. I couldn't find the author's email address on the website.
zoneminder frontdoor exploit found
- zoneminder
- Site Admin
- Posts: 5215
- Joined: Wed Jul 09, 2003 2:07 pm
- Location: Bristol, UK
- Contact: