CVE-2011-4674
Published: 2 December 2011
SQL injection vulnerability in popup.php in Zabbix 1.8.3 and 1.8.4, and possibly other versions before 1.8.9, allows remote attackers to execute arbitrary SQL commands via the only_hostid parameter.
Notes
Author | Note |
---|---|
mdeslaur | May be fixed in 1.8.5, unclear PoC: http://www.exploit-db.com/exploits/18155/ |
Priority
Status
Package | Release | Status |
---|---|---|
zabbix Launchpad, Ubuntu, Debian |
hardy |
Ignored
(end of life)
|
lucid |
Ignored
(end of life)
|
|
maverick |
Ignored
(end of life)
|
|
natty |
Ignored
(end of life)
|
|
oneiric |
Ignored
(end of life)
|
|
precise |
Not vulnerable
(1:1.8.9-1)
|
|
quantal |
Not vulnerable
(1:1.8.9-1)
|
|
raring |
Not vulnerable
(1:1.8.9-1)
|
|
saucy |
Not vulnerable
(1:1.8.9-1)
|
|
upstream |
Released
(1.8.9)
|