CVE-2020-15803
- EPSS 2.09%
- Veröffentlicht 17.07.2020 03:15:11
- Zuletzt bearbeitet 21.11.2024 05:06:12
Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget.
CVE-2013-3738
- EPSS 2.86%
- Veröffentlicht 17.02.2020 16:15:16
- Zuletzt bearbeitet 21.11.2024 01:54:12
A File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, which could let a remote malicious user execute arbitrary code.
CVE-2013-3628
- EPSS 89.62%
- Veröffentlicht 07.02.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 01:54:00
Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability
CVE-2013-5743
- EPSS 82.37%
- Veröffentlicht 11.12.2019 19:15:12
- Zuletzt bearbeitet 21.11.2024 01:58:02
Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7.
CVE-2013-7484
- EPSS 0.21%
- Veröffentlicht 30.11.2019 02:15:10
- Zuletzt bearbeitet 21.11.2024 02:01:07
Zabbix before 5.0 represents passwords in the users table with unsalted MD5.
CVE-2019-17382
- EPSS 93.65%
- Veröffentlicht 09.10.2019 14:15:12
- Zuletzt bearbeitet 21.11.2024 04:32:13
An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass the login page and access the dashboard page, and then create a Dashboard, Report, Screen, or Map without any Username/Password (i...
CVE-2019-15132
- EPSS 0.41%
- Veröffentlicht 17.08.2019 18:15:10
- Zuletzt bearbeitet 21.11.2024 04:28:07
Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is possible to enumerate application usernames based on the variability of server responses (e.g., the "Login name or password is incorrect" and "No permissions for system ac...
CVE-2016-10742
- EPSS 0.41%
- Veröffentlicht 17.02.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 02:44:38
Zabbix before 2.2.21rc1, 3.x before 3.0.13rc1, 3.1.x and 3.2.x before 3.2.10rc1, and 3.3.x and 3.4.x before 3.4.4rc1 allows open redirect via the request parameter.
- EPSS 0.63%
- Veröffentlicht 20.04.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:24:13
In the trapper functionality of Zabbix Server 2.4.x, specifically crafted trapper packets can pass database logic checks, resulting in database writes. An attacker can set up a Man-in-the-Middle server to alter trapper requests made between an active...
CVE-2017-2826
- EPSS 0.26%
- Veröffentlicht 09.04.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:24:13
An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted iConfig proxy request can cause the Zabbix server to send the configuration information of any Zabbix proxy, resulting in informat...