vendor:
Zabbix
by:
Unknown
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Zabbix
Affected Version From: 2.0
Affected Version To: 3.0.4
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux (Debian/CentOS/Ubuntu)
2016
2.0 < Zabbix < 3.0.4 SQL Injection Python PoC
This exploit is a Python PoC for a SQL Injection vulnerability in Zabbix versions 2.0 to 3.0.4. It allows an attacker to extract the username and password of a user, as well as the session ID of a logged in user, by exploiting a vulnerability in the web interface of Zabbix. The exploit is done by sending a malicious payload to the jsrpc.php page of the Zabbix web interface.
Mitigation:
Upgrade to Zabbix 3.0.4 or later, or apply the patch from ZBX-10863.