PT-2013-6134 · Zabbix+1 · Zabbix+1
Publicado
2013-12-09
·
Atualizado
2014-03-06
·
CVE-2013-6824
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Zabbix versions prior to 1.8.19rc1
Zabbix versions prior to 2.0.10rc1
Zabbix versions prior to 2.2.1rc1
Description
The issue allows remote Zabbix servers and proxies to execute arbitrary commands via a newline in a
flexible user parameter. This can be exploited by sending a malicious request to the affected Zabbix server or proxy.Recommendations
For versions prior to 1.8.19rc1, update to version 1.8.19rc1 or later.
For versions prior to 2.0.10rc1, update to version 2.0.10rc1 or later.
For versions prior to 2.2.1rc1, update to version 2.2.1rc1 or later.
Exploit
Correção
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Zabbix