vendor:
Zabbix
by:
hdm
7.5
CVSS
HIGH
Command Injection
78
CWE
Product Name: Zabbix
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2009-4502
CPE: a:zabbix:zabbix
Platforms Tested: Unix
2009
Zabbix Agent net.tcp.listen Command Injection
This module exploits a metacharacter injection vulnerability in the FreeBSD and Solaris versions of the Zabbix agent. This flaw can only be exploited if the attacker can hijack the IP address of an authorized server (as defined in the configuration file).
Mitigation:
Upgrade to the latest version of Zabbix agent.