CVE-2013-3738: Input Validation
Published Feb 17, 2020
·Updated
A File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, which could let a remote malicious user execute arbitrary code.
Affected Software
1 affected component
Zabbix Zabbix=2.0.6
Remediation
Patch Available
Event History
Feb 17, 2020
CVE Published
via MITRE·03:54 PM
Data Sourced
via MITRE·03:54 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-3738?
The severity of CVE-2013-3738 is critical with a score of 9.8.
2
How does CVE-2013-3738 affect Zabbix?
CVE-2013-3738 affects Zabbix version 2.0.6.
3
What is the vulnerability in CVE-2013-3738?
CVE-2013-3738 is a File Inclusion vulnerability in Zabbix 2.0.6.
4
How can a remote attacker exploit CVE-2013-3738?
A remote attacker can exploit CVE-2013-3738 by executing arbitrary code through inadequate sanitization of request strings in CGI scripts.
5
Is there a fix available for CVE-2013-3738?
Yes, a fix for CVE-2013-3738 is available. Please refer to the reference link for more information.