References https://vulapps.evalbug.com/z_zabbix_1/ https://www.cnblogs.com/s0ky1xd/p/5874043.html https://zhuanlan.zhihu.com/p/66248991 https://xxh.ahtcm.edu.cn/info/1201/6141.htm https://zhuanlan.zhihu.com/p/22066760 https://cloud.tencent.com/developer/article/1090969 https://blog.nsfocus.net/sql-zabbix-analysis-protection-scheme-injection-vulnerability/ https://www.secpulse.com/archives/51168.html https://www.cnblogs.com/Fluorescence-tjy/p/5858696.html https://seclists.org/fulldisclosure/2016/Aug/79 https://seclists.org/fulldisclosure/2016/Aug/60 https://www.lightless.me/archives/zabbix-sql-injection.html https://www.anquanke.com/post/id/84406 https://github.com/Medicean/VulApps/wiki/%E6%BC%8F%E6%B4%9E%E7%8E%AF%E5%A2%83%E9%80%9F%E6%9F%A5%E5%88%97%E8%A1%A8
Related VulnerabilitiesZabbix /api_jsonrpc.php SQL 注入漏洞(CVE-2024-36465)PoCCVE-2024-22120: Zabbix Server - Time-Based Blind SQL injectionPoCCVE-2016-10134: Zabbix - SQL InjectionPoCCVE-2019-17382: Zabbix <=4.4 - Authentication BypassPoCCVE-2022-23131: Zabbix - SAML SSO Authentication BypassPoCCVE-2022-23134: Zabbix Setup Configuration Authentication BypassPoCCVE-2022-26148: Grafana & Zabbix Integration - Credentials DisclosurePoCCVE-2016-10134: Zabbix SQL Injection VulnerabilityPoCzabbix-default-password: Zabbix Default Password