CVE-2010-0712: SQL Injection
Published Feb 26, 2010
·Updated
Multiple SQL injection vulnerabilities in zport/dmd/Events/getJSONEventsInfo in Zenoss 2.3.3, and other versions before 2.5, allow remote authenticated users to execute arbitrary SQL commands via the (1) severity, (2) state, (3) filter, (4) offset, and (5) count parameters.
Affected Software
5 affected components
Zenoss Zenoss<=2.4.5
Zenoss Zenoss=2.3.0
Zenoss Zenoss=2.3.3
Zenoss Zenoss=2.4.0
Zenoss Zenoss=2.4.2
Event History
Feb 26, 2010
CVE Published
via MITRE·05:03 PM
Data Sourced
via MITRE·05:03 PM
Description
Data Sourced
via NVD·05:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-0712?
CVE-2010-0712 is classified as a critical SQL injection vulnerability.
2
How do I fix CVE-2010-0712?
To fix CVE-2010-0712, upgrade Zenoss to version 2.5 or later.
3
What versions of Zenoss are affected by CVE-2010-0712?
Zenoss versions 2.3.0 to 2.4.5 are affected by CVE-2010-0712.
4
Can CVE-2010-0712 be exploited by unauthenticated users?
No, CVE-2010-0712 can only be exploited by remote authenticated users.
5
What parameters are involved in the SQL injection of CVE-2010-0712?
CVE-2010-0712 involves SQL injection through the severity, state, filter, offset, and count parameters.