PT-2019-6989 · Zabbix · Zabbix

Bernhard Schildendorfer

+1

·

Published

2014-01-21

·

Updated

2019-12-16

·

CVE-2013-5743

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zabbix versions 1.8.x through 1.8.17 Zabbix versions 2.0.x through 2.0.8 Zabbix versions 2.1.x through 2.1.6
Description The issue involves multiple SQL injection vulnerabilities.
Recommendations For Zabbix versions 1.8.x through 1.8.17, update to version 1.8.18rc1 or later. For Zabbix versions 2.0.x through 2.0.8, update to version 2.0.9rc1 or later. For Zabbix versions 2.1.x through 2.1.6, update to version 2.1.7 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-5743
MGASA-2014-0015

Affected Products

Zabbix