header-logo
Suggest Exploit
vendor:
Zabbix
by:
hdm
7.5
CVSS
HIGH
Command Injection
78
CWE
Product Name: Zabbix
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2009-4502
CPE: a:zabbix:zabbix
Metasploit:
Other Scripts:
Platforms Tested: Unix
2009

Zabbix Agent net.tcp.listen Command Injection

This module exploits a metacharacter injection vulnerability in the FreeBSD and Solaris versions of the Zabbix agent. This flaw can only be exploited if the attacker can hijack the IP address of an authorized server (as defined in the configuration file).

Mitigation:

Upgrade to the latest version of Zabbix agent.
Source

Exploit-DB raw data: