Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Márcio Almeida De Macêdo

Pesquisador deAlligator Security Team
#36568de 53,635
7.5CVSS total
Vulnerabilidades · 1
PT-2011-5021
7.5
2011-12-02
Zabbix · Zabbix · CVE-2011-4674
**Name of the Vulnerable Software and Affected Versions** Zabbix versions 1.8.3 through 1.8.4 and possibly other versions prior to 1.8.9 **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the `only hostid` parameter in the popup.php file. **Recommendations** For versions 1.8.3 and 1.8.4, and possibly other versions prior to 1.8.9, avoid using the `only hostid` parameter in the popup.php file until the issue is resolved. Consider restricting access to the popup.php file to minimize the risk of exploitation.