PatchSiren cyber security CVE debrief
CVE-2016-10204 Zoneminder CVE debrief
CVE-2016-10204 is a critical SQL injection issue in Zoneminder 1.30.0 and earlier. NVD states that a remote attacker can execute arbitrary SQL commands through the limit parameter in a log query request to index.php. The CVE was published on 2017-03-03 and the NVD record was later modified on 2026-05-13.
- Vendor
- Zoneminder
- Product
- Unknown
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-03
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-03
- Advisory updated
- 2026-05-13
Who should care
Zoneminder administrators, security teams, and operators of any deployment running version 1.30.0 or earlier, especially systems exposed to untrusted networks.
Technical summary
NVD classifies the weakness as CWE-89 (SQL Injection) and rates it CVSS 3.0 9.8/CRITICAL with AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The vulnerable surface is a log query request handled by index.php, where the limit parameter can be abused to inject SQL. The affected version range in the NVD CPE data is Zoneminder up to and including 1.30.0.
Defensive priority
Urgent. This is network-reachable, requires no privileges or user interaction, and is scored as critical with high impact across confidentiality, integrity, and availability.
Recommended defensive actions
- Inventory Zoneminder deployments and confirm whether any instance is running 1.30.0 or earlier.
- Upgrade to a patched or supported Zoneminder release newer than 1.30.0.
- Restrict access to the Zoneminder web interface to trusted networks until remediation is complete.
- Review application and database logs for unexpected SQL activity associated with index.php log query requests.
- If exposure is confirmed, validate database integrity and rotate credentials used by the application as part of incident response.
Evidence notes
The source corpus includes the NVD CVE record, which lists the vulnerability status as Modified, the affected CPE range through 1.30.0, CVSS 3.0 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, and CWE-89. References in the corpus include an oss-security mailing list post and a Foxmole advisory; both are tagged as exploit-related references, but this debrief does not rely on them for attack details.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-10204 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-10204
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-10204 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-10204
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.foxmole.com/advisories/foxmole-2016-07-05.txt
[email protected] - Exploit, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.