Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-4338

Опубликовано: 23 янв. 2017
Источник: debian
EPSS Средний

Описание

The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x before 2.2.13, and 3.0.x before 3.0.3, when used with a shell other than bash, allows context-dependent attackers to execute arbitrary code or SQL commands via the mysql.size parameter.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zabbixfixed1:3.0.3+dfsg-1package
zabbixfixed1:2.2.7+dfsg-2+deb8u1jessiepackage

Примечания

  • http://seclists.org/bugtraq/2016/May/11

  • https://support.zabbix.com/browse/ZBX-10741

EPSS

Процентиль: 97%
0.4496
Средний

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 9 лет назад

The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x before 2.2.13, and 3.0.x before 3.0.3, when used with a shell other than bash, allows context-dependent attackers to execute arbitrary code or SQL commands via the mysql.size parameter.

CVSS3: 8.1
nvd
около 9 лет назад

The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x before 2.2.13, and 3.0.x before 3.0.3, when used with a shell other than bash, allows context-dependent attackers to execute arbitrary code or SQL commands via the mysql.size parameter.

CVSS3: 8.1
github
больше 3 лет назад

The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x before 2.2.13, and 3.0.x before 3.0.3, when used with a shell other than bash, allows context-dependent attackers to execute arbitrary code or SQL commands via the mysql.size parameter.

EPSS

Процентиль: 97%
0.4496
Средний