Description
|
|
(#An SQL injection was reported in Zabbix.#An authenticated remote attacker could exploit it in order to access sensitive data inside the database via specially crafted requests.##This vulnerability is triggerable via the "toggle_ids" in the "latest.php" web page.##Updated, 15/08/2016:#A proof of concept is available.#Updated, 08/09/2016:#This vulnerability is also triggerable via the "profileIdx2" parameter.##An exploitation code is available.#Updated, 12/01/2017:#The CVE-2016-10134 identifier has been assigned to this vulnerability.##The zabbix packages provided by Debian Jessie 8 are vulnerable.)
|