CVE-2010-2790
published 2010-08-05CVE-2010-2790: Multiple cross-site scripting (XSS) vulnerabilities in the formatQuery function in frontends/php/include/classes/class.curl.php in Zabbix before 1.8.3rc1 allow…
PriorityP416medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.90%
77.5th percentile
Multiple cross-site scripting (XSS) vulnerabilities in the formatQuery function in frontends/php/include/classes/class.curl.php in Zabbix before 1.8.3rc1 allow remote attackers to inject arbitrary web script or HTML via the (1) filter_set, (2) show_details, (3) filter_rst, or (4) txt_select parameters to the triggers page (tr_status.php). NOTE: some of these details are obtained from third party information.
Affected
50 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zabbix | < zabbix 1:1.8.3-1 (bookworm) | zabbix 1:1.8.3-1 (bookworm) |
| zabbix | zabbix | <= 1.8.2 | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2010-2790: zabbix - Multiple cross-site scripting (XSS) vulnerabilities in the formatQuery function ...
vendor_debian·2010·CVSS 4.3
CVE-2010-2790 [MEDIUM] CVE-2010-2790: zabbix - Multiple cross-site scripting (XSS) vulnerabilities in the formatQuery function ...
Multiple cross-site scripting (XSS) vulnerabilities in the formatQuery function in frontends/php/include/classes/class.curl.php in Zabbix before 1.8.3rc1 allow remote attackers to inject arbitrary web script or HTML via the (1) filter_set, (2) show_details, (3) filter_rst, or (4) txt_select parameters to the triggers page (tr_status.php). NOTE: some of these details are obtained from third party information.
Scope: local
bookworm: resolved (fixed in 1:1.8.3-1)
bullseye: resolved (fixed in 1:1.8.3-1)
forky: resolved (fixed in 1:1.8.3-1)
sid: resolved (fixed in 1:1.8.3-1)
trixie: resolved (fixed in 1:1.8.3-1)
GHSA
GHSA-6f9x-gc6q-v2cg: Multiple cross-site scripting (XSS) vulnerabilities in the formatQuery function in frontends/php/include/classes/class
ghsa_unreviewed·2022-05-17
CVE-2010-2790 [MEDIUM] CWE-79 GHSA-6f9x-gc6q-v2cg: Multiple cross-site scripting (XSS) vulnerabilities in the formatQuery function in frontends/php/include/classes/class
Multiple cross-site scripting (XSS) vulnerabilities in the formatQuery function in frontends/php/include/classes/class.curl.php in Zabbix before 1.8.3rc1 allow remote attackers to inject arbitrary web script or HTML via the (1) filter_set, (2) show_details, (3) filter_rst, or (4) txt_select parameters to the triggers page (tr_status.php). NOTE: some of these details are obtained from third party information.
OSV
CVE-2010-2790: Multiple cross-site scripting (XSS) vulnerabilities in the formatQuery function in frontends/php/include/classes/class
osv·2010-08-05·CVSS 4.3
CVE-2010-2790 [MEDIUM] CVE-2010-2790: Multiple cross-site scripting (XSS) vulnerabilities in the formatQuery function in frontends/php/include/classes/class
Multiple cross-site scripting (XSS) vulnerabilities in the formatQuery function in frontends/php/include/classes/class.curl.php in Zabbix before 1.8.3rc1 allow remote attackers to inject arbitrary web script or HTML via the (1) filter_set, (2) show_details, (3) filter_rst, or (4) txt_select parameters to the triggers page (tr_status.php). NOTE: some of these details are obtained from third party information.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-2790 Zabbix: XSS in triggers page (ZBX-2326)
bugzilla·2010-08-03·CVSS 4.3
CVE-2010-2790 [MEDIUM] CVE-2010-2790 Zabbix: XSS in triggers page (ZBX-2326)
CVE-2010-2790 Zabbix: XSS in triggers page (ZBX-2326)
VUPEN Security Team reported:
[1] http://www.vupen.com/english/advisories/2010/1908
multiple cross-site scripting (XSS) flaws, present in Zabbix code.
An attacker could use this flaw to execute arbitrary scripting code.
References:
[2] https://support.zabbix.com/browse/ZBX-2326
[3] http://www.zabbix.com/forum/showthread.php?p=68770
Discussion:
This issue affects the version of the zabbix package, as shipped
with Fedora release of 13.
Please fix / rebase to Zabbix v1.8.3rc1 / Zabbix v1.8.3rc3 versions.
---
Created zabbix tracking bugs for this issue
Affects: fedora-13 [bug 620809]
---
fixed in
https://admin.fedoraproject.org/updates/zabbix-1.8.2-2.fc13
https://admin.fedoraproject.org/updates/zabbix-1.8.2-3.fc14
http://koji.fed
Bugzilla
CVE-2010-2790 Zabbix: XSS in triggers page (ZBX-2326) [fedora-13]
bugzilla·2010-08-03·CVSS 4.3
CVE-2010-2790 [MEDIUM] CVE-2010-2790 Zabbix: XSS in triggers page (ZBX-2326) [fedora-13]
CVE-2010-2790 Zabbix: XSS in triggers page (ZBX-2326) [fedora-13]
fedora-13 tracking bug for zabbix: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
fixed in https://admin.fedoraproject.org/updates/zabbix-1.8.2-2.fc13
---
This message is a reminder that Fedora 13 is nearing its end of life.
Approximately 30 (thirty) days from now Fedora will stop maintaining
and issuing updates for Fedora 13. It is Fedora's policy to close all
bug reports from releases that are no longer maintained. At that time
this bug will be closed as WONTFIX if it remains open with a Fedora
'version' of '13'.
Package Maintainer: If you wis
http://secunia.com/advisories/40679http://www.securityfocus.com/bid/42017http://www.vupen.com/english/advisories/2010/1908http://www.zabbix.com/forum/showthread.php?p=68770https://exchange.xforce.ibmcloud.com/vulnerabilities/60772https://support.zabbix.com/browse/ZBX-2326http://secunia.com/advisories/40679http://www.securityfocus.com/bid/42017http://www.vupen.com/english/advisories/2010/1908http://www.zabbix.com/forum/showthread.php?p=68770https://exchange.xforce.ibmcloud.com/vulnerabilities/60772https://support.zabbix.com/browse/ZBX-2326
2010-08-05
Published