漏洞描述 zabbix 是一个基于 Web 界面的提供分布式系统监视以及网络监视功能的企业级的开源解决方案。Zabbix的addRelatedObjects 函数存在一个严重漏洞,只具有访问权限的攻击者可以利用该漏洞执行任意sql语句,执行任意代码,导致服务器失陷。
相关漏洞推荐 POC CVE-2024-22120: Zabbix Server - Time-Based Blind SQL injection POC CVE-2016-10134: Zabbix - SQL Injection POC CVE-2019-17382: Zabbix <=4.4 - Authentication Bypass POC CVE-2022-23131: Zabbix - SAML SSO Authentication Bypass POC CVE-2022-23134: Zabbix Setup Configuration Authentication Bypass POC CVE-2022-26148: Grafana & Zabbix Integration - Credentials Disclosure POC CVE-2016-10134: Zabbix SQL Injection Vulnerability POC CVE-2022-23131: Zabbix - SAML SSO Authentication Bypass POC CVE-2022-23134: Zabbix Setup Configuration Authentication Bypass POC CVE-2022-26148: Grafana & Zabbix Integration - Credentials Disclosure POC zabbix-default-password: Zabbix Default Password POC zabbix-authentication-bypass: Zabbix authentication Bypass POC zabbix-dashboards-access: Zabbix Dashboards Access