Lucene search

K
cveMitreCVE-2008-3882
HistorySep 02, 2008 - 3:41 p.m.

CVE-2008-3882

2008-09-0215:41:00
CWE-94
mitre
web.nvd.nist.gov
33
command injection
zoneminder
cve-2008-3882
vulnerability
remote execution

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

High

EPSS

0.005

Percentile

75.8%

Unspecified “Command Injection” vulnerability in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary commands via (1) the executeFilter function in zm_html_view_events.php and (2) the run_state parameter to zm_html_view_state.php.

Affected configurations

Nvd
Node
zoneminderzoneminderRange1.23.3
OR
zoneminderzoneminderMatch0.0.1
OR
zoneminderzoneminderMatch0.9.7
OR
zoneminderzoneminderMatch0.9.8
OR
zoneminderzoneminderMatch0.9.9
OR
zoneminderzoneminderMatch0.9.10
OR
zoneminderzoneminderMatch0.9.11
OR
zoneminderzoneminderMatch0.9.12
OR
zoneminderzoneminderMatch0.9.13
OR
zoneminderzoneminderMatch0.9.14
OR
zoneminderzoneminderMatch0.9.15
OR
zoneminderzoneminderMatch0.9.16
OR
zoneminderzoneminderMatch1.17.0
OR
zoneminderzoneminderMatch1.17.1
OR
zoneminderzoneminderMatch1.17.2
OR
zoneminderzoneminderMatch1.18.0
OR
zoneminderzoneminderMatch1.18.1
OR
zoneminderzoneminderMatch1.19.0
OR
zoneminderzoneminderMatch1.19.1
OR
zoneminderzoneminderMatch1.19.2
OR
zoneminderzoneminderMatch1.19.3
OR
zoneminderzoneminderMatch1.19.4
OR
zoneminderzoneminderMatch1.19.5
OR
zoneminderzoneminderMatch1.20.0
OR
zoneminderzoneminderMatch1.20.1
OR
zoneminderzoneminderMatch1.21.0
OR
zoneminderzoneminderMatch1.21.1
OR
zoneminderzoneminderMatch1.21.2
OR
zoneminderzoneminderMatch1.21.3
OR
zoneminderzoneminderMatch1.21.4
OR
zoneminderzoneminderMatch1.22.0
OR
zoneminderzoneminderMatch1.22.1
OR
zoneminderzoneminderMatch1.22.2
OR
zoneminderzoneminderMatch1.22.3
OR
zoneminderzoneminderMatch1.23.0
OR
zoneminderzoneminderMatch1.23.1
OR
zoneminderzoneminderMatch1.23.2
VendorProductVersionCPE
zoneminderzoneminder*cpe:2.3:a:zoneminder:zoneminder:*:*:*:*:*:*:*:*
zoneminderzoneminder0.0.1cpe:2.3:a:zoneminder:zoneminder:0.0.1:*:*:*:*:*:*:*
zoneminderzoneminder0.9.7cpe:2.3:a:zoneminder:zoneminder:0.9.7:*:*:*:*:*:*:*
zoneminderzoneminder0.9.8cpe:2.3:a:zoneminder:zoneminder:0.9.8:*:*:*:*:*:*:*
zoneminderzoneminder0.9.9cpe:2.3:a:zoneminder:zoneminder:0.9.9:*:*:*:*:*:*:*
zoneminderzoneminder0.9.10cpe:2.3:a:zoneminder:zoneminder:0.9.10:*:*:*:*:*:*:*
zoneminderzoneminder0.9.11cpe:2.3:a:zoneminder:zoneminder:0.9.11:*:*:*:*:*:*:*
zoneminderzoneminder0.9.12cpe:2.3:a:zoneminder:zoneminder:0.9.12:*:*:*:*:*:*:*
zoneminderzoneminder0.9.13cpe:2.3:a:zoneminder:zoneminder:0.9.13:*:*:*:*:*:*:*
zoneminderzoneminder0.9.14cpe:2.3:a:zoneminder:zoneminder:0.9.14:*:*:*:*:*:*:*
Rows per page:
1-10 of 371

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

High

EPSS

0.005

Percentile

75.8%