CVE-2016-10134

CRITICAL NUCLEI

Zabbix <2.2.14, <3.0.4 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php.

Exploits (1)

metasploit WORKING POC
by [email protected], bperry · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/zabbix_toggleids_sqli.rb

Nuclei Templates (1)

Zabbix - SQL Injection
CRITICALby princechaddha
Shodan: http.favicon.hash:892542951 || http.title:"zabbix-server" || cpe:"cpe:2.3:a:zabbix:zabbix"
FOFA: icon_hash=892542951 || app="zabbix-监控系统" && body="saml" || title="zabbix-server"

Scores

CVSS v3 9.8
EPSS 0.8623
EPSS Percentile 99.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (5)
zabbix/zabbix 3.0.0
zabbix/zabbix 3.0.1
zabbix/zabbix 3.0.2
zabbix/zabbix 3.0.3
zabbix/zabbix < 2.2.13
Published Feb 17, 2017
Tracked Since Feb 18, 2026