CVE-2016-10134: SQL Injection
Published Jan 11, 2017
·Updated
SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggleids array parameter in latest.php.
Affected Software
7 affected componentsFixes available
debian/zabbix<=1:2.2.7+dfsg-2+deb8u1, <=1:2.2.7+dfsg-2, <=1:2.2.7+dfsg-1
1:3.0.4+dfsg-11:2.2.7+dfsg-2+deb8u2
Zabbix Zabbix<=2.2.13
Zabbix Zabbix=3.0.0
Zabbix Zabbix=3.0.1
Zabbix Zabbix=3.0.2
Zabbix Zabbix=3.0.3
debian/zabbix
1:5.0.8+dfsg-11:5.0.46+dfsg-1+deb11u11:6.0.14+dfsg-11:7.0.10+dfsg-2
Remediation
Patch Available
Event History
Feb 16, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Feb 17, 2017
Data Sourced
via NVD·02:59 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-10134?
CVE-2016-10134 has a severity rating that indicates it allows remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2016-10134?
To fix CVE-2016-10134, upgrade Zabbix to version 2.2.14 or later, or 3.0.4 or later.
3
Which versions of Zabbix are affected by CVE-2016-10134?
CVE-2016-10134 affects Zabbix versions prior to 2.2.14 and 3.0 prior to 3.0.4.
4
Can I still use Zabbix versions prior to the patched releases if I mitigate CVE-2016-10134?
No, using affected versions without upgrading poses a security risk as the vulnerability remains exploitable.
5
What types of attacks can CVE-2016-10134 facilitate?
CVE-2016-10134 can facilitate SQL injection attacks, allowing unauthorized SQL commands to be executed.