CVE-2010-1277: SQL Injection
Published Apr 6, 2010
·Updated
SQL injection vulnerability in the user.authenticate method in the API in Zabbix 1.8 before 1.8.2 allows remote attackers to execute arbitrary SQL commands via the user parameter in JSON data to apijsonrpc.php.
Affected Software
2 affected components
Zabbix Zabbix=1.8
Zabbix Zabbix=1.8.1
Remediation
Patch Available
Event History
Apr 6, 2010
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-1277?
CVE-2010-1277 is classified as a medium severity SQL injection vulnerability.
2
How do I fix CVE-2010-1277?
To fix CVE-2010-1277, upgrade the Zabbix server to version 1.8.2 or later.
3
What software is affected by CVE-2010-1277?
CVE-2010-1277 affects Zabbix versions 1.8 and 1.8.1.
4
What type of vulnerability is CVE-2010-1277?
CVE-2010-1277 is an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
5
Can CVE-2010-1277 be exploited remotely?
Yes, CVE-2010-1277 can be exploited remotely through the user.authenticate method in the API.