ZABBIX 'node_process_command()' Remote Command Execution Vulnerability
BID:37989
Info
ZABBIX 'node_process_command()' Remote Command Execution Vulnerability
| Bugtraq ID: | 37989 |
| Class: | Design Error |
| CVE: |
CVE-2009-4998 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 13 2009 12:00AM |
| Updated: | Apr 13 2015 10:08PM |
| Credit: | Igor Danoshaites |
| Vulnerable: |
ZABBIX ZABBIX 1.6.7 ZABBIX ZABBIX 1.6.6 ZABBIX ZABBIX 1.6.5 ZABBIX ZABBIX 1.6.3 ZABBIX ZABBIX 1.6.2 |
| Not Vulnerable: |
ZABBIX ZABBIX 1.6.8 ZABBIX ZABBIX 1.8 |
Discussion
ZABBIX 'node_process_command()' Remote Command Execution Vulnerability
ZABBIX is prone to a remote command-execution vulnerability because the software fails to restrict access to sensitive commands.
Successful attacks can compromise the affected software and possibly the computer.
Versions prior to ZABBIX 1.6.8 are vulnerable.
ZABBIX is prone to a remote command-execution vulnerability because the software fails to restrict access to sensitive commands.
Successful attacks can compromise the affected software and possibly the computer.
Versions prior to ZABBIX 1.6.8 are vulnerable.
Exploit / POC
ZABBIX 'node_process_command()' Remote Command Execution Vulnerability
An attacker can exploit this issue using readily available tools.
The following example exploit is available:
An attacker can exploit this issue using readily available tools.
The following example exploit is available:
Solution / Fix
ZABBIX 'node_process_command()' Remote Command Execution Vulnerability
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
ZABBIX 'node_process_command()' Remote Command Execution Vulnerability
References:
References:
- [#ZBX-1030] Remote commands execution in Zabbix Server. (Igor Danoshaites)