Multiple SQL injection vulnerabilities in zport/dmd/Events/getJSONEventsInfo in Zenoss 2.3.3, and other versions prior to 2.5, allow remote authenticated users to execute arbitrary SQL commands via the (1) severity, (2) state, (3) filter, (4) offset, and (5) count parameters.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
zenoss zenoss 2.4.2 |
||
zenoss zenoss |
||
zenoss zenoss 2.3.3 |
||
zenoss zenoss 2.3.0 |
||
zenoss zenoss 2.4.0 |