Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2008-1381Code Injection in Zoneminder

CWE-94Code Injection7 documents7 sources
Severity
7.5HIGHNVD
EPSS
1.5%
top 18.80%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedMay 1
Latest updateMay 1

Description

ZoneMinder before 1.23.3 allows remote authenticated users, and possibly unauthenticated attackers in some installations, to execute arbitrary commands via shell metacharacters in a crafted URL.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

debiandebian/zoneminder< zoneminder 1.23.3-1 (bookworm)
Debianzoneminder/zoneminder< 1.23.3-1+3
NVDzoneminder/zoneminder36 versions+35

🔴Vulnerability Details

2
GHSA
GHSA-5qh7-p4hh-vm8p: ZoneMinder before 12022-05-01
OSV
CVE-2008-1381: ZoneMinder before 12008-05-01

💥Exploits & PoCs

1
Exploit-DB
airVisionNVR 1.1.13 - 'readfile()' Disclosure / SQL Injection2012-10-15

📋Vendor Advisories

2
Red Hat
zoneminder: command injection via unescaped php exec() calls2008-04-27
Debian
CVE-2008-1381: zoneminder - ZoneMinder before 1.23.3 allows remote authenticated users, and possibly unauthe...2008

💬Community

1
Bugzilla
CVE-2008-1381 zoneminder: command injection via unescaped php exec() calls2008-04-28