Two Sinks, One Shell: OS Command Injection in ZoneMinder
ZoneMinder's event export concatenates monitor names directly into shell commands. One unsanitized source, two exec() sinks, and a payload that someone else can trigger for you.
Iinvestigato
2 min readvulnerability-researchphpcommand-injectionzoneminderrce