First published: Thu Dec 31 2009(Updated: )
SQL injection vulnerability in the get_history_lastid function in the nodewatcher component in Zabbix Server before 1.6.8 allows remote attackers to execute arbitrary SQL commands via a crafted request, possibly related to the send_history_last_id function in zabbix_server/trapper/nodehistory.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zabbix Server | =1.1.2 | |
Zabbix Server | =1.1.4 | |
Zabbix Server | =1.4.3 | |
Zabbix Server | <=1.6.7 | |
Zabbix Server | =1.4.6 | |
Zabbix Server | =1.4.4 | |
Zabbix Server | =1.1.3 | |
Zabbix Server | =1.6.6 | |
Zabbix Server | =1.4.2 | |
Zabbix Server | =1.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4499 is considered to have high severity due to its potential for remote exploitation.
To fix CVE-2009-4499, upgrade your Zabbix Server to version 1.6.8 or later.
CVE-2009-4499 affects all Zabbix versions prior to 1.6.8.
CVE-2009-4499 is an SQL injection vulnerability that allows execution of arbitrary SQL commands.
Yes, CVE-2009-4499 can be exploited remotely by attackers through crafted requests.