Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL injection vulnerability in the user.authenticate method in the API in Zabbix 1.8 before 1.8.2 allows remote attackers to execute arbitrary SQL commands via the user parameter in JSON data to api_jsonrpc.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Zabbix 方法'user.authenticate'SQL注入漏洞
Vulnerability Description
Zabbix是拉脱维亚Zabbix SIA公司的一套开源的监控系统。该系统可监视各种网络参数,并提供通知机制让系统管理员快速定位、解决存在的各种问题。 Zabbix的API(应用程序接口)的user.authenticate方法存在SQL注入漏洞。远程攻击者可以通过提供给脚本api_jsonrpc.php的JSON数据中的'user'参数,执行任意的SQL指令。
CVSS Information
N/A
Vulnerability Type
N/A