VulnerabilityModified
CVE-2010-1277
SQL injection vulnerability in the user.authenticate method in the API in Zabbix 1.8 before 1.8.2 allows remote attackers to execute arbitrary SQL commands via the user parameter in JSON data to api_jsonrpc.php.
HIGH 7.5EPSS 1.74%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.74%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SQL injection vulnerability in the user.authenticate method in the API in Zabbix 1.8 before 1.8.2 allows remote attackers to execute arbitrary SQL commands via the user parameter in JSON data to api_jsonrpc.php.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.74% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- zabbix/zabbix
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0001.htmlExploit
- http://legalhackers.com/advisories/zabbix181api-sql.txtExploit
- http://legalhackers.com/poc/zabbix181api.pl-pocExploit
- http://secunia.com/advisories/39119Vendor Advisory
- http://www.osvdb.org/63456
- http://www.securityfocus.com/archive/1/510480/100/0/threaded
- http://www.securityfocus.com/bid/39148Exploit
- http://www.vupen.com/english/advisories/2010/0799Vendor Advisory
- http://www.zabbix.com/rn1.8.2.phpPatch
- http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0001.htmlExploit
- http://legalhackers.com/advisories/zabbix181api-sql.txtExploit
- http://legalhackers.com/poc/zabbix181api.pl-pocExploit
- http://secunia.com/advisories/39119Vendor Advisory
- http://www.osvdb.org/63456
- http://www.securityfocus.com/archive/1/510480/100/0/threaded
- http://www.securityfocus.com/bid/39148Exploit
- http://www.vupen.com/english/advisories/2010/0799Vendor Advisory
- http://www.zabbix.com/rn1.8.2.phpPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.