#VU33555 SQL injection - CVE-2016-10134
Published: February 17, 2017 / Updated: August 4, 2020
Description
The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data passed via the toggle_ids array parameter in latest.php. A remote attacker can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database.
Successful exploitation of this vulnerability may allow a remote attacker to read, delete, modify data in database and gain complete control over the affected application.
Remediation
External links
- http://www.debian.org/security/2017/dsa-3802
- http://www.openwall.com/lists/oss-security/2017/01/12/4
- http://www.openwall.com/lists/oss-security/2017/01/13/4
- http://www.securityfocus.com/bid/95423
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=850936
- https://code610.blogspot.com/2017/10/zbx-11023-quick-autopsy.html
- https://support.zabbix.com/browse/ZBX-11023