vendor:
ZABBIX
by:
Ulf Harnhammar
7.5
CVSS
HIGH
Buffer Overflow/Format String
119
CWE
Product Name: ZABBIX
Affected Version From: 1.1.2002
Affected Version To: Other versions may be affected
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Debian
2006
ZABBIX Multiple Unspecified Remote Code-Execution Vulnerabilities
ZABBIX is prone to multiple unspecified remote code-execution vulnerabilities. Reports indicate that these issues facilitate format-string and buffer-overflow attacks. A remote attacker may leverage these vulnerabilities to trigger denial-of-service conditions or to execute arbitrary code to gain unauthorized access to a vulnerable computer. This would occur in the context of the application. ZABBIX version 1.1.2 is reported vulnerable; other versions may be affected as well.
Mitigation:
Upgrade to the latest version of ZABBIX