PT-2013-6134 · Zabbix+1 · Zabbix+1

Publicado

2013-12-09

·

Atualizado

2014-03-06

·

CVE-2013-6824

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Zabbix versions prior to 1.8.19rc1 Zabbix versions prior to 2.0.10rc1 Zabbix versions prior to 2.2.1rc1
Description The issue allows remote Zabbix servers and proxies to execute arbitrary commands via a newline in a flexible user parameter. This can be exploited by sending a malicious request to the affected Zabbix server or proxy.
Recommendations For versions prior to 1.8.19rc1, update to version 1.8.19rc1 or later. For versions prior to 2.0.10rc1, update to version 2.0.10rc1 or later. For versions prior to 2.2.1rc1, update to version 2.2.1rc1 or later.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2013-1261
CVE-2013-6824
MGASA-2014-0015

Produtos afetados

Alt Linux
Zabbix