PT-2009-6606 · Zabbix · Zabbix Server+1

Igor Danoshaites

·

Published

2009-12-31

·

Updated

2010-02-02

·

CVE-2009-4499

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Zabbix Server versions prior to 1.6.8
Description A SQL injection issue exists in the get history lastid function within the nodewatcher component, allowing remote attackers to execute arbitrary SQL commands via a crafted request. This issue may be related to the send history last id function in zabbix server/trapper/nodehistory.c.
Recommendations For versions prior to 1.6.8, update to version 1.6.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the nodewatcher component to minimize the risk of exploitation.

Exploit

Fix

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-4499

Affected Products

Zabbix
Zabbix Server