daemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters.Referenceshttps://github.com/LoRexxar/CVE_Request/tree/master/zoneminder%20vul%20before%20v1.32.3#includesfunctionsphp-daemoncontrol-command-injection