← Vulnerability feed

Vulnerability record · CVE-2008-3882 · published 2 September 2008

CVE-2008-3882: Zoneminder code injection vulnerability

Zoneminder · Zoneminder

Unspecified "Command Injection" vulnerability in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary commands via (1) the executeFilter function in zm_html_view_events.php and (2) the run_state parameter to zm_html_view_state.php.

10.0 CVSS 2.0 High EPSS 3.5% · top 11.3% CWE-94 · Code injection
10.0CVSS 2.0 base score
3.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

Unspecified "Command Injection" vulnerability in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary commands via (1) the executeFilter function in zm_html_view_events.php and (2) the run_state parameter to zm_html_view_state.php.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-3882 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-65791Zoneminder os command injection vulnerabilityZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user input directly to the exec() f…EPSS 1.7%9.8CVE-2024-43360Zoneminder sql injection vulnerabilityZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability.…EPSS 6.2%9.8CVE-2023-26035ZoneMinder snapshot action missing authorization leads to RCEZoneMinder versions before 1.36.33 and 1.37.33 lack a permissions check on the snapshot action, which accepts an id meant to fetch an existing monito…EPSS 80%analysed9.8CVE-2023-26036Zoneminder untrusted search path vulnerabilityZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior …EPSS 0.90%9.8CVE-2023-26037Zoneminder sql injection vulnerabilityZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior …EPSS 0.61%9.8CVE-2022-29806ZoneMinder path traversal in language setting enables remote code executionZoneMinder before 1.36.13 allows remote code execution through an invalid language value, with a path traversal weakness (CWE-22) that lets an attack…EPSS 67%analysed9.8CVE-2019-8423Zoneminder sql injection vulnerabilityZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter.EPSS 1.6%9.8CVE-2019-8424Zoneminder sql injection vulnerabilityZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2008-3882), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.