CVE-2010-1277 Information
Feb 14, 2021
cve
Description
SQL injection vulnerability in the user.authenticate method in the API in Zabbix 1.8 before 1.8.2 allows remote attackers to execute arbitrary SQL commands via the user parameter in JSON data to api_jsonrpc.php.
Reference
http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0001.html http://legalhackers.com/advisories/zabbix181api-sql.txt http://legalhackers.com/poc/zabbix181api.pl-poc http://secunia.com/advisories/39119 http://www.osvdb.org/63456 http://www.securityfocus.com/archive/1/510480/100/0/threaded http://www.securityfocus.com/bid/39148 http://www.vupen.com/english/advisories/2010/0799 http://www.zabbix.com/rn1.8.2.php
Share on: