ZABBIX Denial Of Service and SQL Injection Vulnerabilities
BID:37309
Info
ZABBIX Denial Of Service and SQL Injection Vulnerabilities
| Bugtraq ID: | 37309 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2009-4999 CVE-2009-4501 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 14 2009 12:00AM |
| Updated: | Apr 13 2015 08:26PM |
| Credit: | Igor Danoshaites and Alexander Vladishev |
| Vulnerable: |
ZABBIX ZABBIX 1.6.7 ZABBIX ZABBIX 1.6.6 ZABBIX ZABBIX 1.6.5 ZABBIX ZABBIX 1.6.3 ZABBIX ZABBIX 1.6.2 ZABBIX ZABBIX 1.4.3 ZABBIX ZABBIX 1.4.2 ZABBIX ZABBIX 1.1.5 ZABBIX ZABBIX 1.1.4 ZABBIX ZABBIX 1.1.3 ZABBIX ZABBIX 1.1.2 |
| Not Vulnerable: |
ZABBIX ZABBIX 1.6.8 |
Discussion
ZABBIX Denial Of Service and SQL Injection Vulnerabilities
ZABBIX is prone to a denial-of-service vulnerability and an SQL-injection vulnerability.
Successful exploits may allow remote attackers to crash the affected application, exploit latent vulnerabilities in the underlying database, access or modify data, or compromise the application.
Versions prior to ZABBIX 1.6.6 are vulnerable.
ZABBIX is prone to a denial-of-service vulnerability and an SQL-injection vulnerability.
Successful exploits may allow remote attackers to crash the affected application, exploit latent vulnerabilities in the underlying database, access or modify data, or compromise the application.
Versions prior to ZABBIX 1.6.6 are vulnerable.
Exploit / POC
ZABBIX Denial Of Service and SQL Injection Vulnerabilities
An attacker can use readily available network utilities to exploit the denial-of-service issue. The attacker can use a browser to exploit the SQL-injection issue.
An attacker can use readily available network utilities to exploit the denial-of-service issue. The attacker can use a browser to exploit the SQL-injection issue.
Solution / Fix
ZABBIX Denial Of Service and SQL Injection Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
ZABBIX Denial Of Service and SQL Injection Vulnerabilities
References:
References:
- [#ZBX-1031] Remote SQL injection in Zabbix Server. (Igor Danoshaites)
- [#ZBX-1355] Possible server crash if data received in incorrect format (Alexander Vladishev)