SQL injection vulnerability in Zoneminder 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the limit parameter in a log query request to index.php.
https://github.com/dc-333-666/CVE-2016-10204_Webshell
https://github.com/0xNullComet/CVE-2016-10204_Webshell
https://www.foxmole.com/advisories/foxmole-2016-07-05.txt