PT-2013-6134 · Zabbix+1 · Zabbix+1
Published
2013-12-09
·
Updated
2014-03-06
·
CVE-2013-6824
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Zabbix versions prior to 1.8.19rc1
Zabbix versions prior to 2.0.10rc1
Zabbix versions prior to 2.2.1rc1
Description
The issue allows remote Zabbix servers and proxies to execute arbitrary commands via a newline in a
flexible user parameter. This can be exploited by sending a malicious request to the affected Zabbix server or proxy.Recommendations
For versions prior to 1.8.19rc1, update to version 1.8.19rc1 or later.
For versions prior to 2.0.10rc1, update to version 2.0.10rc1 or later.
For versions prior to 2.2.1rc1, update to version 2.2.1rc1 or later.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Zabbix