Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2008-3881
Disclosure Date: September 02, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in ZoneMinder 1.23.3 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified "zm_html_view_*.php" files.
0
Attacker Value
Unknown
CVE-2008-3880
Disclosure Date: September 02, 2008 (last updated October 04, 2023)
SQL injection vulnerability in zm_html_view_event.php in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary SQL commands via the filter array parameter.
0
Attacker Value
Unknown
CVE-2008-3882
Disclosure Date: September 02, 2008 (last updated October 04, 2023)
Unspecified "Command Injection" vulnerability in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary commands via (1) the executeFilter function in zm_html_view_events.php and (2) the run_state parameter to zm_html_view_state.php.
0
Attacker Value
Unknown
CVE-2008-1381
Disclosure Date: May 01, 2008 (last updated October 04, 2023)
ZoneMinder before 1.23.3 allows remote authenticated users, and possibly unauthenticated attackers in some installations, to execute arbitrary commands via shell metacharacters in a crafted URL.
0
Attacker Value
Unknown
CVE-2004-0227
Disclosure Date: June 14, 2004 (last updated February 22, 2025)
Buffer overflow in the zms script in ZoneMinder before 1.19.2 may allow a remote attacker to execute arbitrary code via a long query string.
0