CVE-2014-9450: SQL Injection
Multiple SQL injection vulnerabilities in chartbar.php in the frontend in Zabbix before 1.8.22, 2.0.x before 2.0.14, and 2.2.x before 2.2.8 allow remote attackers to execute arbitrary SQL commands via the (1) itemid or (2) periods parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9450?
CVE-2014-9450 has a high severity rating due to its potential for remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2014-9450?
To fix CVE-2014-9450, upgrade Zabbix to version 1.8.22 or later, 2.0.14 or later, or 2.2.8 or later.
What versions of Zabbix are affected by CVE-2014-9450?
CVE-2014-9450 affects Zabbix versions before 1.8.22, 2.0.x before 2.0.14, and 2.2.x before 2.2.8.
Can CVE-2014-9450 impact my Zabbix installation?
Yes, if you are using an affected version of Zabbix, CVE-2014-9450 can allow unauthorized access to your database.
What type of vulnerability is CVE-2014-9450?
CVE-2014-9450 is classified as a SQL injection vulnerability, allowing attackers to manipulate SQL queries.