7.5
CVSSv2

CVE-2008-3880

Published: 02/09/2008 Updated: 11/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in zm_html_view_event.php in ZoneMinder 1.23.3 and previous versions allows remote malicious users to execute arbitrary SQL commands via the filter array parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

zoneminder zoneminder 0.9.14

zoneminder zoneminder 0.9.15

zoneminder zoneminder 1.17.2

zoneminder zoneminder 1.18.0

zoneminder zoneminder 1.19.5

zoneminder zoneminder 1.20.0

zoneminder zoneminder 1.22.1

zoneminder zoneminder 1.22.2

zoneminder zoneminder 0.0.1

zoneminder zoneminder 0.9.10

zoneminder zoneminder 0.9.11

zoneminder zoneminder 0.9.8

zoneminder zoneminder 0.9.9

zoneminder zoneminder 0.9.12

zoneminder zoneminder 0.9.13

zoneminder zoneminder 1.17.0

zoneminder zoneminder 1.17.1

zoneminder zoneminder 1.19.3

zoneminder zoneminder 1.19.4

zoneminder zoneminder 1.21.4

zoneminder zoneminder 1.22.0

zoneminder zoneminder

zoneminder zoneminder 1.19.1

zoneminder zoneminder 1.19.2

zoneminder zoneminder 1.21.2

zoneminder zoneminder 1.21.3

zoneminder zoneminder 1.23.1

zoneminder zoneminder 1.23.2

zoneminder zoneminder 0.9.16

zoneminder zoneminder 0.9.7

zoneminder zoneminder 1.18.1

zoneminder zoneminder 1.19.0

zoneminder zoneminder 1.20.1

zoneminder zoneminder 1.21.0

zoneminder zoneminder 1.21.1

zoneminder zoneminder 1.22.3

zoneminder zoneminder 1.23.0

Vendor Advisories

Debian Bug report logs - #497640 zoneminder: Several security issues (XSS, SQL injection, Command injection) Package: zoneminder; Maintainer for zoneminder is Dmitry Smirnov <onlyjob@debianorg>; Source for zoneminder is src:zoneminder (PTS, buildd, popcon) Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> D ...
Debian Bug report logs - #528252 zoneminder: conf file permissions need to be more restrictive Package: zoneminder; Maintainer for zoneminder is Dmitry Smirnov <onlyjob@debianorg>; Source for zoneminder is src:zoneminder (PTS, buildd, popcon) Reported by: "Michael S Gilbert" <michaelsgilbert@gmailcom> Date: Mon, ...

Exploits

airVisionNVR version 1113 suffers from readfile() disclosure and remote SQL injection vulnerabilities ...