PT-2013-6134 · Zabbix+1 · Zabbix+1

Published

2013-12-09

·

Updated

2014-03-06

·

CVE-2013-6824

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Zabbix versions prior to 1.8.19rc1 Zabbix versions prior to 2.0.10rc1 Zabbix versions prior to 2.2.1rc1
Description The issue allows remote Zabbix servers and proxies to execute arbitrary commands via a newline in a flexible user parameter. This can be exploited by sending a malicious request to the affected Zabbix server or proxy.
Recommendations For versions prior to 1.8.19rc1, update to version 1.8.19rc1 or later. For versions prior to 2.0.10rc1, update to version 2.0.10rc1 or later. For versions prior to 2.2.1rc1, update to version 2.2.1rc1 or later.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2013-1261
CVE-2013-6824
MGASA-2014-0015

Affected Products

Alt Linux
Zabbix