LWN.net Logo

zabbix: SQL injection

Package(s):zabbix CVE #(s):CVE-2012-3435
Created:August 31, 2012 Updated:January 1, 2013
Description: From the CVE entry:

SQL injection vulnerability in frontends/php/popup_bitem.php in Zabbix 1.8.15rc1 and earlier, and 2.x before 2.0.2rc1, allows remote attackers to execute arbitrary SQL commands via the itemid parameter.

Alerts:
Fedora FEDORA-2012-12496 2012-08-31
Fedora FEDORA-2012-12488 2012-08-31
Debian DSA-2539-1 2012-09-06
Mageia MGASA-2012-0370 2012-12-31

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds