Language:
https://support.zabbix.com/browse/ZBX-5348
Severity: High
ID: 62757
File Name: zabbix_frontend_itemid_sqli.nasl
Version: 1.13
Type: remote
Family: CGI abuses
Published: 10/30/2012
Updated: 4/4/2025
Configuration: Enable thorough checks (optional)
Supported Sensors: Nessus
Enable CGI Scanning: true
CVSS Score Rationale: Score based on an in-depth analysis of the vendor advisory.
Risk Factor: High
Score: 7.4
Risk Factor: High
Base Score: 7.5
Temporal Score: 6.5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS Score Source: manual
CPE: cpe:/a:zabbix:zabbix
Required KB Items: www/zabbix
Excluded KB Items: Settings/disable_cgi_scanning
Exploit Available: true
Exploit Ease: No exploit is required
Exploited by Nessus: true
Patch Publication Date: 7/19/2012
Vulnerability Publication Date: 7/18/2012
Elliot (Zabbix 2.0 SQL Injection)
CVE: CVE-2012-3435
BID: 54661