Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
Link | Tags |
---|---|
https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-tricks-and-treats | third party advisory exploit |
https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-foss-disclosures-part-one | third party advisory |
http://www.securityfocus.com/bid/63453 | vdb entry third party advisory |
http://www.exploit-db.com/exploits/29321 | vdb entry third party advisory |