漏洞描述 Zabbix是一个提供分布式系统监视以及网络监视功能的解决方案。由于Zabbix的Ping脚本未对输入的脚本参数进行转义或验证,登录管理员账号的攻击者可构造特定输入通过Ping脚本执行任意代码,进而控制服务器。受影响版本为6.4.0-6.4.15, 7.0.0alpha1-7.0.0rc2。
相关漏洞推荐 Zabbix /api_jsonrpc.php SQL 注入漏洞(CVE-2024-36465) POC CVE-2024-22120: Zabbix Server - Time-Based Blind SQL injection POC CVE-2016-10134: Zabbix - SQL Injection POC CVE-2019-17382: Zabbix <=4.4 - Authentication Bypass POC CVE-2022-23131: Zabbix - SAML SSO Authentication Bypass POC CVE-2022-23134: Zabbix Setup Configuration Authentication Bypass POC CVE-2022-26148: Grafana & Zabbix Integration - Credentials Disclosure POC CVE-2016-10134: Zabbix SQL Injection Vulnerability POC CVE-2022-23131: Zabbix - SAML SSO Authentication Bypass POC CVE-2022-23134: Zabbix Setup Configuration Authentication Bypass POC CVE-2022-26148: Grafana & Zabbix Integration - Credentials Disclosure POC zabbix-default-password: Zabbix Default Password POC zabbix-authentication-bypass: Zabbix authentication Bypass