CVE-2008-3882
published 2008-09-02CVE-2008-3882: Unspecified "Command Injection" vulnerability in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary commands via (1) the executeFilter…
PriorityP354critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.48%
87.7th percentile
Unspecified "Command Injection" vulnerability in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary commands via (1) the executeFilter function in zm_html_view_events.php and (2) the run_state parameter to zm_html_view_state.php.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zoneminder | < zoneminder 1.24.1-1 (bookworm) | zoneminder 1.24.1-1 (bookworm) |
| zoneminder | zoneminder | <= 1.23.3 | — |
| zoneminder | zoneminder | — | — |
| zoneminder | zoneminder | — | — |
| zoneminder | zoneminder | — | — |
| zoneminder | zoneminder | — | — |
| zoneminder | zoneminder | — | — |
| zoneminder | zoneminder | — | — |
| zoneminder | zoneminder | — | — |
| zoneminder | zoneminder | — | — |
| zoneminder | zoneminder | — | — |
| zoneminder | zoneminder | — | — |
| zoneminder | zoneminder | — | — |
| zoneminder | zoneminder | — | — |
| zoneminder | zoneminder | — | — |
| zoneminder | zoneminder | — | — |
| zoneminder | zoneminder | — | — |
| zoneminder | zoneminder | — | — |
| zoneminder | zoneminder | — | — |
| zoneminder | zoneminder | — | — |
| zoneminder | zoneminder | — | — |
| zoneminder | zoneminder | — | — |
| zoneminder | zoneminder | — | — |
| zoneminder | zoneminder | — | — |
| zoneminder | zoneminder | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cvgp-9gf8-257q: Unspecified "Command Injection" vulnerability in ZoneMinder 1
ghsa_unreviewed·2022-05-02
CVE-2008-3882 [HIGH] CWE-94 GHSA-cvgp-9gf8-257q: Unspecified "Command Injection" vulnerability in ZoneMinder 1
Unspecified "Command Injection" vulnerability in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary commands via (1) the executeFilter function in zm_html_view_events.php and (2) the run_state parameter to zm_html_view_state.php.
OSV
CVE-2008-3882: Unspecified "Command Injection" vulnerability in ZoneMinder 1
osv·2008-09-02·CVSS 10.0
CVE-2008-3882 [CRITICAL] CVE-2008-3882: Unspecified "Command Injection" vulnerability in ZoneMinder 1
Unspecified "Command Injection" vulnerability in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary commands via (1) the executeFilter function in zm_html_view_events.php and (2) the run_state parameter to zm_html_view_state.php.
Red Hat
zoneminder: command injection, SQL injection and multiple XSS issues (CVE-2008-3882, CVE-2008-3880, CVE-2008-3881)
vendor_redhat·2008-08-26·CVSS 7.5
CVE-2008-3880 [HIGH] CWE-77 zoneminder: command injection, SQL injection and multiple XSS issues (CVE-2008-3882, CVE-2008-3880, CVE-2008-3881)
zoneminder: command injection, SQL injection and multiple XSS issues (CVE-2008-3882, CVE-2008-3880, CVE-2008-3881)
SQL injection vulnerability in zm_html_view_event.php in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary SQL commands via the filter array parameter.
Debian
CVE-2008-3882: zoneminder - Unspecified "Command Injection" vulnerability in ZoneMinder 1.23.3 and earlier a...
vendor_debian·2008·CVSS 10.0
CVE-2008-3882 [CRITICAL] CVE-2008-3882: zoneminder - Unspecified "Command Injection" vulnerability in ZoneMinder 1.23.3 and earlier a...
Unspecified "Command Injection" vulnerability in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary commands via (1) the executeFilter function in zm_html_view_events.php and (2) the run_state parameter to zm_html_view_state.php.
Scope: local
bookworm: resolved (fixed in 1.24.1-1)
bullseye: resolved (fixed in 1.24.1-1)
forky: resolved (fixed in 1.24.1-1)
sid: resolved (fixed in 1.24.1-1)
trixie: resolved (fixed in 1.24.1-1)
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/31636http://www.securityfocus.com/archive/1/495745/100/0/threadedhttp://www.securityfocus.com/bid/30843https://exchange.xforce.ibmcloud.com/vulnerabilities/44728http://secunia.com/advisories/31636http://www.securityfocus.com/archive/1/495745/100/0/threadedhttp://www.securityfocus.com/bid/30843https://exchange.xforce.ibmcloud.com/vulnerabilities/44728
2008-09-02
Published