Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-22120

Опубликовано: 17 мая 2024
Источник: ubuntu
Приоритет: medium
EPSS Критический
CVSS3: 9.1

Описание

Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.

РелизСтатусПримечание
devel

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/xenial

needs-triage

esm-infra-legacy/trusty

needs-triage

focal

ignored

end of standard support, was needs-triage
jammy

needs-triage

mantic

ignored

end of life, was needs-triage
noble

DNE

Показывать по

EPSS

Процентиль: 100%
0.92259
Критический

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
nvd
почти 2 года назад

Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.

CVSS3: 9.1
debian
почти 2 года назад

Zabbix server can perform command execution for configured scripts. Af ...

CVSS3: 9.1
github
почти 2 года назад

Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.

CVSS3: 9.1
fstec
почти 2 года назад

Уязвимость сервера универсальной системы мониторинга Zabbix Workstation, связанная с ошибками при обработке входных данных, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.1
redos
почти 2 года назад

Уязвимость zabbix

EPSS

Процентиль: 100%
0.92259
Критический

9.1 Critical

CVSS3