First published: Tue Apr 06 2010(Updated: )
SQL injection vulnerability in the user.authenticate method in the API in Zabbix 1.8 before 1.8.2 allows remote attackers to execute arbitrary SQL commands via the user parameter in JSON data to api_jsonrpc.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zabbix Server | =1.8 | |
Zabbix Server | =1.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1277 is classified as a medium severity SQL injection vulnerability.
To fix CVE-2010-1277, upgrade the Zabbix server to version 1.8.2 or later.
CVE-2010-1277 affects Zabbix versions 1.8 and 1.8.1.
CVE-2010-1277 is an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
Yes, CVE-2010-1277 can be exploited remotely through the user.authenticate method in the API.