CVE-2016-10134

Name
CVE-2016-10134
Description
SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
security@debian.org http://www.debian.org/security/2017/dsa-3802
Mailing List http://www.openwall.com/lists/oss-security/2017/01/12/4
Mailing List http://www.openwall.com/lists/oss-security/2017/01/13/4
Third Party Advisory http://www.securityfocus.com/bid/95423
Third Party Advisory https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=850936
security@debian.org https://code610.blogspot.com/2017/10/zbx-11023-quick-autopsy.html
Exploit https://support.zabbix.com/browse/ZBX-11023

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* zabbix >= None <= 2.2.13
cpe:2.3:a:zabbix:zabbix:3.0.0:*:*:*:*:*:*:* zabbix == None == 3.0.0
cpe:2.3:a:zabbix:zabbix:3.0.1:*:*:*:*:*:*:* zabbix == None == 3.0.1
cpe:2.3:a:zabbix:zabbix:3.0.2:*:*:*:*:*:*:* zabbix == None == 3.0.2
cpe:2.3:a:zabbix:zabbix:3.0.3:*:*:*:*:*:*:* zabbix == None == 3.0.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status