Vulnerabilities > Zabbix > High

DATE CVE VULNERABILITY TITLE RISK
2010-04-06 CVE-2010-1277 SQL Injection vulnerability in Zabbix 1.8/1.8.1
SQL injection vulnerability in the user.authenticate method in the API in Zabbix 1.8 before 1.8.2 allows remote attackers to execute arbitrary SQL commands via the user parameter in JSON data to api_jsonrpc.php.
network
low complexity
zabbix CWE-89
7.5
2009-12-31 CVE-2009-4499 SQL Injection vulnerability in Zabbix
SQL injection vulnerability in the get_history_lastid function in the nodewatcher component in Zabbix Server before 1.6.8 allows remote attackers to execute arbitrary SQL commands via a crafted request, possibly related to the send_history_last_id function in zabbix_server/trapper/nodehistory.c.
network
low complexity
zabbix CWE-89
7.5