Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2016-10204 PoC — ZoneMinder SQL注入漏洞

Source
Associated Vulnerability
Title:ZoneMinder SQL注入漏洞 (CVE-2016-10204)
Description:ZoneMinder是一套开源的视频监控软件系统。该系统支持IP、USB和模拟摄像机等。 ZoneMinder 1.30及之前的版本中存在SQL注入漏洞,该漏洞源于index.php脚本没有充分过滤‘limit’参数。远程攻击者可通过发送日志查询请求利用该漏洞执行任意的SQL命令。
Description
A bash script demonstrating the manual exploitation of CVE-2016-10204 against a target endpoint, leading to upload of a php webshell.
File Snapshot

None
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.