CVE-2014-9450

Zabbix <1.8.22, <2.0.14, <2.2.8 - SQL Injection

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in chart_bar.php in the frontend in Zabbix before 1.8.22, 2.0.x before 2.0.14, and 2.2.x before 2.2.8 allow remote attackers to execute arbitrary SQL commands via the (1) itemid or (2) periods parameter.

References (5)

Core 5
Core References
Vendor Advisory x_refsource_confirm
http://www.zabbix.com/rn1.8.22.php
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61554
Vendor Advisory x_refsource_confirm
https://support.zabbix.com/browse/ZBX-8582
Vendor Advisory x_refsource_confirm
http://www.zabbix.com/rn2.0.14.php
Vendor Advisory x_refsource_confirm
http://www.zabbix.com/rn2.2.8.php

Scores

EPSS 0.0129
EPSS Percentile 67.2%

Details

CWE
CWE-89
Status published
Products (19)
zabbix/zabbix 2.0.1 (3 CPE variants)
zabbix/zabbix 2.0.2 (3 CPE variants)
zabbix/zabbix 2.0.3 (3 CPE variants)
zabbix/zabbix 2.0.4 (2 CPE variants)
zabbix/zabbix 2.0.5 (2 CPE variants)
zabbix/zabbix 2.0.6 (2 CPE variants)
zabbix/zabbix 2.0.7 rc1
zabbix/zabbix 2.0.8 (3 CPE variants)
zabbix/zabbix 2.0.9 rc1 (2 CPE variants)
zabbix/zabbix 2.0.10 (2 CPE variants)
... and 9 more
Published Jan 02, 2015
Tracked Since Feb 18, 2026