CVE-2024-51482 is a boolean-based SQL injection vulnerability in ZoneMinder affecting version 1.37.* through 1.37.64, inclusive. The flaw is present in the web/ajax/event.php component, where insufficient neutralization of attacker-controlled input in SQL queries allows crafted input to alter query logic. Successful exploitation enables an attacker to perform inference-based database manipulation and extraction through boolean conditions. In exposed or reachable ZoneMinder deployments, this can be used to enumerate or retrieve sensitive application data stored in the backend database.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
8 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (5 hidden).
This repository is a small, focused proof-of-concept exploit for CVE-2024-51482 affecting ZoneMinder. It contains one Python exploit script, a README with vulnerability and usage details, and an editor settings file. The exploit is not part of a larger offensive framework. The main script, CVE-2024-51482.py, implements an authenticated time-based blind SQL injection against the ZoneMinder removetag request flow. It sends GET requests to the ZoneMinder endpoint /index.php?view=request&request=event&action=removetag with a malicious tid parameter and a required id=1 parameter. The script measures response timing to determine whether injected SQL conditions are true by leveraging SLEEP(). Core capabilities: - Performs a baseline timing request. - Confirms exploitability with a sleep-based test payload. - Uses boolean inference over timing responses to evaluate arbitrary SQL conditions. - Determines string lengths with binary search. - Extracts characters one-by-one using ASCII/SUBSTRING comparisons and binary search. - Counts rows in zm.Users. - Dumps Username and Password values from zm.Users, yielding usernames and password hashes. The exploit requires a valid authenticated ZMSESSID cookie, so this is an authenticated web attack rather than unauthenticated RCE. There is no shell payload or post-exploitation automation; the outcome is credential/hash disclosure from the backend database. Because it includes working extraction logic but no customizable framework integration or broader weaponization, the maturity is best classified as POC. Repository structure: - CVE-2024-51482.py: main exploit logic and CLI entry point. - README.md: explains the vulnerable code path, prerequisites, usage examples, and expected output. - .vscode/settings.json: unrelated editor configuration. Notable implementation details: - The send() function constructs the vulnerable request and measures elapsed time. - check() wraps a conditional SLEEP() payload for boolean inference. - get_length() and extract_char() use binary search to reduce requests. - get_users() enumerates rows from zm.Users and extracts Username and Password fields. - The README notes that id=1 is necessary because a preceding DELETE must complete successfully before the vulnerable SELECT is reached.
This repository is a real Python proof-of-concept exploit for CVE-2024-51482, an authenticated time-based blind SQL injection in ZoneMinder’s removetag functionality. The main exploit logic is in exploit.py, which provides a CLI for authenticating with username/password or a supplied ZMSESSID cookie, optionally checking vulnerability status, then enumerating databases, tables, columns, or dumping table contents. The exploit is not just a detector: it performs character-by-character timed extraction of backend SQL data and supports CSV export, making it an operational PoC rather than a simple check script. Repository structure is small and focused: exploit.py is the primary entry point; requirements.txt only depends on requests; README.md documents the vulnerability, usage, and expected output; docker-compose.yml plus docker/Dockerfile and docker/entrypoint.sh create a reproducible lab environment with ZoneMinder 1.37.64 and MariaDB. The Docker lab enables authentication, initializes the schema, and inserts a low-privileged test user, demonstrating the exploit against a realistic vulnerable setup. The primary target surface is the authenticated ZoneMinder web endpoint /zm/index.php, specifically requests using view=request, request=event, action=removetag, with SQL injection delivered through the tid parameter. The exploit’s capabilities include vulnerability verification, database enumeration, table and column discovery, dumping arbitrary tables, and specifically dumping zm.Users to recover credential hashes. No RCE or shell payload is present; the payload is SQL-based data exfiltration via timing side channels.
This repository is a small, focused exploit proof-of-concept for an authenticated time-based blind SQL injection against ZoneMinder, apparently developed for the Hack The Box 'CCTV' machine. The repository contains three files: a short README describing the reliability approach, exp.py containing the exploit logic, and dump.txt containing example extracted data. The Python script is the only code file and the clear entry point. The exploit logs into a ZoneMinder instance using supplied credentials, then abuses the /zm/index.php handler by sending GET requests with view=request, request=event, action=removetag, and a malicious tid parameter. The tid value is crafted as a SQL expression using SELECT SLEEP(...) predicates. The script first determines the length of a target result and then recovers each character by testing ASCII thresholds. It uses a binary-search style inference method and repeats each measurement multiple times, selecting the most frequent result to reduce timing noise and improve reliability. The code is operational rather than a minimal PoC because it automates login, session handling, repeated timing checks, binary search, and output persistence. However, the payloads are hardcoded for specific enumeration tasks rather than being fully generalized into a reusable framework. The demonstrated workflow enumerates database names from information_schema.SCHEMATA, table names from information_schema.TABLES for schema zm, column names from information_schema.COLUMNS for table Users, and finally Name and Password values from zm.Users. The included dump.txt shows successful extraction of schema names, table names, column names, usernames, and bcrypt-style password hashes. Notable implementation details: the script spoofs browser-like headers, uses requests.Session for cookie persistence, assumes HTTP rather than HTTPS, hardcodes host cctv.htb and credentials admin/admin in main, and writes results to a hardcoded local filesystem path. Overall, the repository's purpose is to reliably dump backend ZoneMinder database contents through authenticated blind SQL injection over the network.
Repository contains a single Python exploit script plus README and MIT license. The main file `CVE-2024-51482.py` is an operational PoC/exploitation tool for CVE-2024-51482 affecting ZoneMinder (README claims ≤ 1.37.64), targeting the `removetag` action where `tid` is unsafely concatenated into an SQL query. The script performs time-based blind SQL injection over HTTP GET by injecting a `UNION SELECT IF(condition,SLEEP(DELAY),0)` expression into `tid`, measuring response time to infer boolean outcomes. It first measures baseline latency, then uses binary search on `ASCII(SUBSTRING(...))` to extract characters efficiently, and parallelizes extraction with `ThreadPoolExecutor` (configurable `THREADS`). Capabilities include: extracting current DB (`SELECT database()`), enumerating all schemata via `information_schema.schemata`, enumerating tables and columns for selected databases/tables, caching column lists, and dumping up to 20 rows of selected columns from chosen tables. The tool is interactive (menus for DB/table/column selection) and requires a valid `ZMSESSID` cookie to be set in the script.
Repository contains a single Python exploit script (Exploit.py) and a README describing CVE-2024-51482 (ZoneMinder 1.37.* through 1.37.64). The exploit targets an authenticated SQL injection in the ZoneMinder event tag removal flow (action=removetag) where the tid parameter is concatenated into a SQL query. Exploit.py implements a high-performance time-based blind SQL injection extractor. It uses requests.Session with a user-supplied ZMSESSID cookie, calibrates a response-time threshold, and then sends repeated GET requests to the ZoneMinder index.php endpoint with parameters view=request&request=event&action=removetag and an injected tid value that wraps conditions in SLEEP(IF(...)) to infer true/false. The script is optimized for speed via (1) parallel character extraction using a ThreadPoolExecutor (default 5 workers), (2) character-frequency prioritization (tries common characters first), and (3) fast length discovery (described in README; code indicates length/row existence checks and per-character extraction). Primary capability is database data exfiltration, specifically dumping entries from the zm.Users table and outputting them as Username:Password. It supports dumping a single specified username or iterating through multiple rows until no more data is found. Results are printed and saved to extracted_data.txt, and the script tracks total request count and elapsed time.
Repository contains a single Python PoC/exploit script (`CVE-2024-51482.py`) and a detailed `README.md`. The script targets CVE-2024-51482 in ZoneMinder (v1.37.0–1.37.64), an authenticated blind SQL injection in the `removetag` action where the `tid` parameter is concatenated into an SQL query. Core capabilities: - Authenticates to the ZoneMinder web interface (`/zm/index.php`) using provided credentials and maintains a `requests.Session` (checks for `ZMSESSID`). - Measures baseline response time, then verifies vulnerability using a time-delay payload with `SLEEP(n)`. - Performs time-based blind extraction using boolean conditions and binary search over `ASCII(SUBSTRING(...))` to reconstruct strings. - Supports enumeration and dumping workflows (as indicated by the CLI and README): discover databases, enumerate tables/columns, dump arbitrary table data, and a convenience mode to dump `zm.Users` (usernames, password hashes, and possibly email/enabled fields). Exploit flow/structure: - `ZoneMinderExploit` class encapsulates login, request sending to the vulnerable endpoint, baseline calibration, vulnerability check, and (in truncated portion but evidenced by CLI/README) enumeration/dumping helpers. - `main()` implements an argparse-driven CLI with modes like `--test`, `--discover`, `--tables <db>`, `--columns <db> <table>`, `--dump <db> <table> <col1,col2,...>`, and `--users`, plus tuning options like `--sleep` and `--debug`. No external C2 infrastructure is present; all network interaction is directed at the user-supplied target host over HTTP under the `/zm` path.
Repository contains a single Python proof-of-concept exploit (poc.py) plus documentation (README.md) targeting CVE-2024-51482 in ZoneMinder (v1.37.* through 1.37.64). The exploit is an authenticated, time-based blind SQL injection against ZoneMinder’s event management request handler, specifically the removetag action where the tid parameter is injectable. Structure & purpose: - README.md: Explains affected versions, required authentication, and provides sqlmap-like usage examples for enumerating DBs/tables/columns and dumping data; default goal is dumping zm.Users credentials. - poc.py: Implements the exploit logic end-to-end: authentication (username/password login to /zm/index.php or use an existing ZMSESSID), a vulnerability check using SLEEP timing, then extraction primitives to infer query results. Exploit capabilities (as implemented): - Authenticated exploitation via requests.Session; verifies auth by presence of ZMSESSID cookie. - Vulnerability verification by measuring response delay from a simple SLEEP(2) payload. - Generic time-based blind extraction: - Binary search for LENGTH(query) to determine string size. - Character-by-character extraction using ASCII(SUBSTRING(...)) with a binary search per character. - Parallelized extraction using ThreadPoolExecutor (default 5 threads) to speed up per-position character recovery. - Higher-level enumeration/dumping workflows (per README and visible main flow): enumerate databases, tables, columns, and dump table rows; default mode attempts to dump Username/Password from zm.Users. Notable operational details: - Uses a conditional delay pattern: SLEEP(TIME_DELAY - IF(condition,0,TIME_DELAY)) so TRUE conditions return quickly and FALSE conditions incur the full delay. - Timing threshold uses (TIME_DELAY - 0.3) seconds to account for jitter; delay/threads are tunable for accuracy vs speed. No evidence of destructive actions (e.g., file deletion) or post-exploitation persistence; the primary outcome is database data exfiltration via blind SQLi.
This repository contains a proof-of-concept (PoC) exploit for CVE-2024-51482, a boolean-based blind SQL injection vulnerability in ZoneMinder v1.37.* up to 1.37.64. The exploit is implemented in a single Python script (poc.py) and is accompanied by a detailed README.md explaining usage and the vulnerability. The script targets the /zm/index.php endpoint with specific parameters, exploiting the 'tid' parameter in the 'removetag' action of the 'event' request. It allows an attacker to enumerate MySQL database names, tables, columns, and dump data (such as usernames and password hashes) from the ZoneMinder database. The exploit can run in default mode (dumping users and password hashes) or in an interactive discovery mode for full database exploration. The code is a classic blind SQLi extractor, using binary search to extract data character by character via HTTP requests. No authentication is required for exploitation. The repository is well-structured, with clear separation between documentation and exploit code.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The content only references CVE-2024-51482 by filename/path and does not provide any substantive description of the vulnerability.
Boolean-based SQL injection vulnerability in ZoneMinder affecting 1.37.x versions up to and including 1.37.64, specifically in web/ajax/event.php.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.