7.5
CVSSv2

CVE-2010-1277

Published: 06/04/2010 Updated: 10/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the user.authenticate method in the API in Zabbix 1.8 prior to 1.8.2 allows remote malicious users to execute arbitrary SQL commands via the user parameter in JSON data to api_jsonrpc.php.

Vulnerable Product Search on Vulmon Subscribe to Product

zabbix zabbix 1.8

zabbix zabbix 1.8.1

Vendor Advisories

Debian Bug report logs - #577058 CVE-2010-1277: SQL injection vulnerability Package: zabbix; Maintainer for zabbix is Dmitry Smirnov <onlyjob@debianorg>; Reported by: Giuseppe Iuculano <iuculano@debianorg> Date: Fri, 9 Apr 2010 09:33:05 UTC Severity: grave Tags: security Fixed in version zabbix/1:182-1 Done: C ...