Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2010-1277
Description:SQL injection vulnerability in the user.authenticate method in the API in Zabbix 1.8 before 1.8.2 allows remote attackers to execute arbitrary SQL commands via the user parameter in JSON data to api_jsonrpc.php.
Test IDs: 1.3.6.1.4.1.25623.1.0.100566  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2010-1277
BugTraq ID: 39148
http://www.securityfocus.com/bid/39148
Bugtraq: 20100401 Zabbix <= 1.8.1 SQL Injection (Google Search)
http://www.securityfocus.com/archive/1/510480/100/0/threaded
http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0001.html
http://legalhackers.com/advisories/zabbix181api-sql.txt
http://legalhackers.com/poc/zabbix181api.pl-poc
http://www.zabbix.com/rn1.8.2.php
http://www.osvdb.org/63456
http://secunia.com/advisories/39119
http://www.vupen.com/english/advisories/2010/0799




© 1998-2025 E-Soft Inc. All rights reserved.