Description Zabbix 2.2.14以及之前的版本,3.0.4以及之前的3.0版本中存在SQL注入漏洞。远程攻击者可通过latest.php请求中的toggle_ids参数执行任意SQL命令。
References https://nvd.nist.gov/vuln/detail/CVE-2016-10134 https://www.cve.org/CVERecord?id=CVE-2016-10134 https://security-tracker.debian.org/tracker/CVE-2016-10134 https://ubuntu.com/security/CVE-2016-10134 https://github.com/vulhub/vulhub/blob/master/zabbix/CVE-2016-10134/README.md https://github.com/vulhub/vulhub/blob/master/zabbix/CVE-2016-10134/README.zh-cn.md https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2016/CVE-2016-10134.yaml https://github.com/advisories/GHSA-q33m-pmcq-844x https://sploitus.com/exploit?id=5C6D5A9B-1412-5131-809C-6312C7E86FAD https://security.snyk.io/vuln/SNYK-UNMANAGED-ZABBIXZABBIX-2364962 https://www.cnblogs.com/cute-puli/p/15659959.html
Related VulnerabilitiesZabbix /api_jsonrpc.php SQL 注入漏洞(CVE-2024-36465)PoCCVE-2024-22120: Zabbix Server - Time-Based Blind SQL injectionPoCCVE-2016-10134: Zabbix - SQL InjectionPoCCVE-2019-17382: Zabbix <=4.4 - Authentication BypassPoCCVE-2022-23131: Zabbix - SAML SSO Authentication BypassPoCCVE-2022-23134: Zabbix Setup Configuration Authentication BypassPoCCVE-2022-26148: Grafana & Zabbix Integration - Credentials DisclosurePoCCVE-2016-10134: Zabbix SQL Injection VulnerabilityPoCzabbix-default-password: Zabbix Default Password