CVE-2016-10204: SQL Injection
Published Mar 3, 2017
·Updated
SQL injection vulnerability in Zoneminder 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the limit parameter in a log query request to index.php.
Affected Software
1 affected component
ZoneMinder Zoneminder<=1.30.0
Event History
Mar 3, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-10204?
CVE-2016-10204 is classified as a high-severity SQL injection vulnerability.
2
How do I fix CVE-2016-10204?
To fix CVE-2016-10204, upgrade your ZoneMinder software to version 1.31 or later.
3
What are the implications of CVE-2016-10204?
CVE-2016-10204 allows remote attackers to execute arbitrary SQL commands, potentially leading to data exposure or corruption.
4
Which versions of ZoneMinder are affected by CVE-2016-10204?
ZoneMinder versions 1.30 and earlier are affected by CVE-2016-10204.
5
Can CVE-2016-10204 be exploited remotely?
Yes, CVE-2016-10204 can be exploited remotely through manipulated log query requests.