7.5
CVSSv2

CVE-2008-1381

Published: 01/05/2008 Updated: 08/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

ZoneMinder prior to 1.23.3 allows remote authenticated users, and possibly unauthenticated attackers in some installations, to execute arbitrary commands via shell metacharacters in a crafted URL.

Vulnerable Product Search on Vulmon Subscribe to Product

zoneminder zoneminder 0.9.10

zoneminder zoneminder 0.9.11

zoneminder zoneminder 0.9.8

zoneminder zoneminder 0.9.9

zoneminder zoneminder 1.19.2

zoneminder zoneminder 1.19.3

zoneminder zoneminder 1.21.2

zoneminder zoneminder 1.21.3

zoneminder zoneminder 1.23.1

zoneminder zoneminder 1.23.2

zoneminder zoneminder 0.9.14

zoneminder zoneminder 0.9.15

zoneminder zoneminder 1.17.2

zoneminder zoneminder 1.18.0

zoneminder zoneminder 1.20.0

zoneminder zoneminder 1.20.1

zoneminder zoneminder 1.22.1

zoneminder zoneminder 1.22.2

zoneminder zoneminder 0.9.12

zoneminder zoneminder 0.9.13

zoneminder zoneminder 1.17.0

zoneminder zoneminder 1.17.1

zoneminder zoneminder 1.19.4

zoneminder zoneminder 1.19.5

zoneminder zoneminder 1.21.4

zoneminder zoneminder 1.22.0

zoneminder zoneminder 0.0.1

zoneminder zoneminder 0.9.16

zoneminder zoneminder 0.9.7

zoneminder zoneminder 1.18.1

zoneminder zoneminder 1.19.0

zoneminder zoneminder 1.19.1

zoneminder zoneminder 1.21.0

zoneminder zoneminder 1.21.1

zoneminder zoneminder 1.22.3

zoneminder zoneminder 1.23.0

Vendor Advisories

Debian Bug report logs - #479034 zoneminder: CVE-2008-1381 arbitrary code execution via crafted URL Package: zoneminder; Maintainer for zoneminder is Dmitry Smirnov <onlyjob@debianorg>; Source for zoneminder is src:zoneminder (PTS, buildd, popcon) Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> Date: Fri, ...

Exploits

airVisionNVR version 1113 suffers from readfile() disclosure and remote SQL injection vulnerabilities ...