Zabbix CVE-2014-3005 XML External Entity Injection Vulnerability
BID:68075
CVE-2014-3005 |Info
Zabbix CVE-2014-3005 XML External Entity Injection Vulnerability
| Bugtraq ID: | 68075 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3005 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 17 2014 12:00AM |
| Updated: | Apr 13 2015 08:26PM |
| Credit: | pnig0s |
| Vulnerable: |
ZABBIX ZABBIX 1.8.9 ZABBIX ZABBIX 1.8.7 ZABBIX ZABBIX 1.8.6 ZABBIX ZABBIX 1.8.4 ZABBIX ZABBIX 1.8.3 rc1 ZABBIX ZABBIX 1.8.3 ZABBIX ZABBIX 1.8.2 ZABBIX ZABBIX 1.8.1 ZABBIX ZABBIX 1.8.5 ZABBIX ZABBIX 1.8.3 Rc3 ZABBIX ZABBIX 1.8.3 Rc2 ZABBIX ZABBIX 1.8.10rc ZABBIX ZABBIX 1.8 |
| Not Vulnerable: | |
Discussion
Zabbix CVE-2014-3005 XML External Entity Injection Vulnerability
Zabbix is prone to an XML External Entity injection vulnerability.
Attackers can exploit this issue to obtain potentially sensitive information. This may lead to further attacks.
Zabbix 1.8 through 2.2 are vulnerable.
Zabbix is prone to an XML External Entity injection vulnerability.
Attackers can exploit this issue to obtain potentially sensitive information. This may lead to further attacks.
Zabbix 1.8 through 2.2 are vulnerable.
Exploit / POC
Zabbix CVE-2014-3005 XML External Entity Injection Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
Zabbix CVE-2014-3005 XML External Entity Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Zabbix CVE-2014-3005 XML External Entity Injection Vulnerability
References:
References: