A SQL injection vulnerability exists in Zoneminder 1.30 and earlier, specifically in the handling of the 'limit' parameter in log query requests to index.php. This allows remote attackers to inject and execute arbitrary SQL commands against the backend database.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This four-file repository contains a single operational Python exploit (`zm-exploit.py`), a README, MIT license, and Python cache ignore rules. The script targets CVE-2016-10204 in ZoneMinder 1.29.0/1.30.0 and automates a full unauthenticated SQL injection-to-RCE chain. It first POSTs a stacked SQL `SLEEP(10)` payload in the `limit` parameter to verify the vulnerable log-query endpoint. It then hex-encodes a PHP command webshell and attempts to write it with MySQL `SELECT ... INTO DUMPFILE` to four common Apache/ZoneMinder web roots. After identifying a reachable dropped shell with a randomized echo token, it prompts the operator to start netcat and instructs the webshell to run a Bash TCP reverse shell. A `--cleanup` mode attempts to remove a named webshell via `rm -f`. HTTPS certificate validation is disabled for all requests. The script uses randomized eight-character PHP filenames to avoid MySQL DUMPFILE's non-overwrite behavior. It is not a framework module and includes a hardcoded but operator-parameterized reverse-shell payload, making it operational rather than merely a proof of concept.
This repository contains a Bash script (CVE-2016-10204_Webshell.sh) that exploits CVE-2016-10204, a blind SQL injection vulnerability in ZoneMinder. The script takes two arguments: a webshell URL suffix and the target ZoneMinder index.php URL. It first checks if a webshell already exists on the target. If not, it crafts a malicious SQL injection payload that writes a PHP webshell to /var/www/html/webshell_<suffix>.php on the target server. The script then verifies the webshell's deployment by accessing it and executing the 'id' command via the ?cmd= parameter. The exploit is operational, providing a working webshell for remote command execution. The repository includes a README with detailed usage instructions and a LICENSE file. The main attack vector is network-based, targeting the HTTP endpoint of ZoneMinder. The script is self-contained and does not rely on any external frameworks.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.