SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php.
CVSS Details
- CVSS 3.0 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade zabbix | Oct 1, 2024 | Feb 16, 2017 |
| Debian | — | Upgrade zabbix | Mar 6, 2017 | Feb 16, 2017 |
| Ubuntu | — | Upgrade zabbix-proxy-mysql (Ubuntu Pro)Upgrade zabbix-proxy-pgsql (Ubuntu Pro)Upgrade zabbix-frontend-php (Ubuntu Pro)Upgrade zabbix-server-pgsql (Ubuntu Pro)Upgrade zabbix-proxy-sqlite3 (Ubuntu Pro)Upgrade zabbix-agent (Ubuntu Pro)Upgrade zabbix-server-mysql (Ubuntu Pro)Upgrade zabbix-java-gateway (Ubuntu Pro) | Mar 22, 2023 | Feb 17, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub