0xNullComet

1 exploit Active since Mar 2017
CVE-2016-10204 NOMISEC CRITICAL WORKING POC
ZoneMinder < 1.30.0 - SQL Injection via Log Query Limit Parameter
SQL injection vulnerability in Zoneminder 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the limit parameter in a log query request to index.php.
2 stars
CVSS 9.8