7.5
CVSSv2

CVE-2009-4499

Published: 31/12/2009 Updated: 02/02/2010
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the get_history_lastid function in the nodewatcher component in Zabbix Server prior to 1.6.8 allows remote malicious users to execute arbitrary SQL commands via a crafted request, possibly related to the send_history_last_id function in zabbix_server/trapper/nodehistory.c.

Vulnerable Product Search on Vulmon Subscribe to Product

zabbix zabbix 1.6.6

zabbix zabbix 1.4.3

zabbix zabbix 1.4.2

zabbix zabbix 1.1.5

zabbix zabbix 1.1.4

zabbix zabbix

zabbix zabbix 1.1.2

zabbix zabbix 1.4.4

zabbix zabbix 1.1.3

zabbix zabbix 1.4.6

Exploits

Zabbix Server : Multiple remote vulnerabilities From: Nicob <nicob () nicob net> Date: Sun, 13 Dec 2009 16:28:35 +0100 From Wikipedia : "Zabbix is a network management system application [] designed to monitor and track the status of various network services, servers, and other network hardware" [Zabbix Server : Remote command executio ...