#VU33112 SQL injection - CVE-2012-3435
Published: August 15, 2012 / Updated: August 4, 2020
Description
The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data passed via the itemid parameter. A remote attacker can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database.
Successful exploitation of this vulnerability may allow a remote attacker to read, delete, modify data in database and gain complete control over the affected application.
Remediation
External links
- http://git.zabbixzone.com/zabbix2.0/.git/commitdiff/333a3a5542ba8a2c901c24b7bf5440f41f1f4f54
- http://osvdb.org/84127
- http://secunia.com/advisories/49809
- http://secunia.com/advisories/50475
- http://www.debian.org/security/2012/dsa-2539
- http://www.exploit-db.com/exploits/20087
- http://www.openwall.com/lists/oss-security/2012/07/27/6
- http://www.openwall.com/lists/oss-security/2012/07/28/3
- http://www.securityfocus.com/bid/54661
- https://exchange.xforce.ibmcloud.com/vulnerabilities/77195
- https://support.zabbix.com/browse/ZBX-5348