5
CVSSv2

CVE-2013-1364

Published: 14/12/2013 Updated: 16/12/2013
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The user.login function in Zabbix prior to 1.8.16 and 2.x prior to 2.0.5rc1 allows remote malicious users to override LDAP configuration via the cnf parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

zabbix zabbix 2.0.0

zabbix zabbix 2.0.4

zabbix zabbix 2.0.3

zabbix zabbix 2.0.2

zabbix zabbix 2.0.1

zabbix zabbix

Vendor Advisories

Debian Bug report logs - #698541 zabbix: CVE-2013-1364: possible to override LDAP configuration parameters via the API Package: zabbix; Maintainer for zabbix is Dmitry Smirnov <onlyjob@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 20 Jan 2013 07:30:02 UTC Severity: grave Tags: security ...