Lucene search

K
cve[email protected]CVE-2012-3435
HistoryAug 15, 2012 - 8:55 p.m.

CVE-2012-3435

2012-08-1520:55:03
CWE-89
web.nvd.nist.gov
31
cve-2012-3435
sql injection
zabbix
remote execution
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.2 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

59.2%

SQL injection vulnerability in frontends/php/popup_bitem.php in Zabbix 1.8.15rc1 and earlier, and 2.x before 2.0.2rc1, allows remote attackers to execute arbitrary SQL commands via the itemid parameter.

Affected configurations

NVD
Node
zabbixzabbixRange1.8.15rc1
OR
zabbixzabbixMatch1.1
OR
zabbixzabbixMatch1.1beta10
OR
zabbixzabbixMatch1.1beta11
OR
zabbixzabbixMatch1.1beta12
OR
zabbixzabbixMatch1.1beta2
OR
zabbixzabbixMatch1.1beta3
OR
zabbixzabbixMatch1.1beta4
OR
zabbixzabbixMatch1.1beta5
OR
zabbixzabbixMatch1.1beta6
OR
zabbixzabbixMatch1.1beta7
OR
zabbixzabbixMatch1.1beta8
OR
zabbixzabbixMatch1.1beta9
OR
zabbixzabbixMatch1.1.1
OR
zabbixzabbixMatch1.1.2
OR
zabbixzabbixMatch1.1.3
OR
zabbixzabbixMatch1.1.4
OR
zabbixzabbixMatch1.1.5
OR
zabbixzabbixMatch1.1.6
OR
zabbixzabbixMatch1.1.7
OR
zabbixzabbixMatch1.3beta
OR
zabbixzabbixMatch1.3.1beta
OR
zabbixzabbixMatch1.3.2beta
OR
zabbixzabbixMatch1.3.3beta
OR
zabbixzabbixMatch1.3.4beta
OR
zabbixzabbixMatch1.3.5beta
OR
zabbixzabbixMatch1.3.6beta
OR
zabbixzabbixMatch1.3.7beta
OR
zabbixzabbixMatch1.3.8beta
OR
zabbixzabbixMatch1.4.2
OR
zabbixzabbixMatch1.4.3
OR
zabbixzabbixMatch1.4.4
OR
zabbixzabbixMatch1.4.5
OR
zabbixzabbixMatch1.4.6
OR
zabbixzabbixMatch1.5beta
OR
zabbixzabbixMatch1.5.1beta
OR
zabbixzabbixMatch1.5.2beta
OR
zabbixzabbixMatch1.5.3beta
OR
zabbixzabbixMatch1.5.4beta
OR
zabbixzabbixMatch1.6
OR
zabbixzabbixMatch1.6.1
OR
zabbixzabbixMatch1.6.2
OR
zabbixzabbixMatch1.6.3
OR
zabbixzabbixMatch1.6.4
OR
zabbixzabbixMatch1.6.5
OR
zabbixzabbixMatch1.6.6
OR
zabbixzabbixMatch1.6.7
OR
zabbixzabbixMatch1.6.8
OR
zabbixzabbixMatch1.6.9
OR
zabbixzabbixMatch1.7
OR
zabbixzabbixMatch1.7.1
OR
zabbixzabbixMatch1.7.2
OR
zabbixzabbixMatch1.7.3
OR
zabbixzabbixMatch1.7.4
OR
zabbixzabbixMatch1.8
OR
zabbixzabbixMatch1.8.1
OR
zabbixzabbixMatch1.8.2
OR
zabbixzabbixMatch1.8.3rc1
OR
zabbixzabbixMatch1.8.3rc2
OR
zabbixzabbixMatch1.8.3rc3
OR
zabbixzabbixMatch2.0.0
OR
zabbixzabbixMatch2.0.0rc1
OR
zabbixzabbixMatch2.0.0rc2
OR
zabbixzabbixMatch2.0.0rc3
OR
zabbixzabbixMatch2.0.0rc4
OR
zabbixzabbixMatch2.0.0rc5
OR
zabbixzabbixMatch2.0.0rc6
OR
zabbixzabbixMatch2.0.1
OR
zabbixzabbixMatch2.0.1rc1
OR
zabbixzabbixMatch2.0.1rc2

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.2 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

59.2%