CVE-2014-9450
published 2015-01-02CVE-2014-9450: Multiple SQL injection vulnerabilities in chart_bar.php in the frontend in Zabbix before 1.8.22, 2.0.x before 2.0.14, and 2.2.x before 2.2.8 allow remote…
PriorityP345high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.29%
67.0th percentile
Multiple SQL injection vulnerabilities in chart_bar.php in the frontend in Zabbix before 1.8.22, 2.0.x before 2.0.14, and 2.2.x before 2.2.8 allow remote attackers to execute arbitrary SQL commands via the (1) itemid or (2) periods parameter.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zabbix | < zabbix 1:2.2.7+dfsg-2 (bookworm) | zabbix 1:2.2.7+dfsg-2 (bookworm) |
| zabbix | zabbix | <= 1.8.21 | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | — | — |
| zabbix | zabbix | >= 0 < 1:2.2.7+dfsg-2 | 1:2.2.7+dfsg-2 |
| zabbix | zabbix | >= 0 < 1:2.2.7+dfsg-2 | 1:2.2.7+dfsg-2 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rq9v-pgww-544v: Multiple SQL injection vulnerabilities in chart_bar
ghsa_unreviewed·2022-05-17
CVE-2014-9450 [HIGH] CWE-89 GHSA-rq9v-pgww-544v: Multiple SQL injection vulnerabilities in chart_bar
Multiple SQL injection vulnerabilities in chart_bar.php in the frontend in Zabbix before 1.8.22, 2.0.x before 2.0.14, and 2.2.x before 2.2.8 allow remote attackers to execute arbitrary SQL commands via the (1) itemid or (2) periods parameter.
OSV
CVE-2014-9450: Multiple SQL injection vulnerabilities in chart_bar
osv·2015-01-02·CVSS 7.5
CVE-2014-9450 [HIGH] CVE-2014-9450: Multiple SQL injection vulnerabilities in chart_bar
Multiple SQL injection vulnerabilities in chart_bar.php in the frontend in Zabbix before 1.8.22, 2.0.x before 2.0.14, and 2.2.x before 2.2.8 allow remote attackers to execute arbitrary SQL commands via the (1) itemid or (2) periods parameter.
Debian
CVE-2014-9450: zabbix - Multiple SQL injection vulnerabilities in chart_bar.php in the frontend in Zabbi...
vendor_debian·2014·CVSS 7.5
CVE-2014-9450 [HIGH] CVE-2014-9450: zabbix - Multiple SQL injection vulnerabilities in chart_bar.php in the frontend in Zabbi...
Multiple SQL injection vulnerabilities in chart_bar.php in the frontend in Zabbix before 1.8.22, 2.0.x before 2.0.14, and 2.2.x before 2.2.8 allow remote attackers to execute arbitrary SQL commands via the (1) itemid or (2) periods parameter.
Scope: local
bookworm: resolved (fixed in 1:2.2.7+dfsg-2)
bullseye: resolved (fixed in 1:2.2.7+dfsg-2)
forky: resolved (fixed in 1:2.2.7+dfsg-2)
sid: resolved (fixed in 1:2.2.7+dfsg-2)
trixie: resolved (fixed in 1:2.2.7+dfsg-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-9450 zabbix20: zabbix: SQL injection in chart_bar.php [epel-7]
bugzilla·2015-01-05·CVSS 7.5
CVE-2014-9450 [HIGH] CVE-2014-9450 zabbix20: zabbix: SQL injection in chart_bar.php [epel-7]
CVE-2014-9450 zabbix20: zabbix: SQL injection in chart_bar.php [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 tracking bug for zabbix20: see blocks bug list for
Bugzilla
CVE-2014-9450 zabbix22: zabbix: SQL injection in chart_bar.php [epel-7]
bugzilla·2015-01-05·CVSS 7.5
CVE-2014-9450 [HIGH] CVE-2014-9450 zabbix22: zabbix: SQL injection in chart_bar.php [epel-7]
CVE-2014-9450 zabbix22: zabbix: SQL injection in chart_bar.php [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 tracking bug for zabbix22: see blocks bug list for
Bugzilla
CVE-2014-9450 zabbix20: zabbix: SQL injection in chart_bar.php [epel-6]
bugzilla·2015-01-05·CVSS 7.5
CVE-2014-9450 [HIGH] CVE-2014-9450 zabbix20: zabbix: SQL injection in chart_bar.php [epel-6]
CVE-2014-9450 zabbix20: zabbix: SQL injection in chart_bar.php [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-6 tracking bug for zabbix20: see blocks bug list for
Bugzilla
CVE-2014-9450 zabbix: SQL injection in chart_bar.php
bugzilla·2015-01-05·CVSS 7.5
CVE-2014-9450 [HIGH] CVE-2014-9450 zabbix: SQL injection in chart_bar.php
CVE-2014-9450 zabbix: SQL injection in chart_bar.php
Multiple SQL injection flaws were discovered[1] in Zabbix's chart_bar.php front end code. Either of these flaws could allow a remote attacker to execute arbitrary SQL commands using the itemid or periods parameters.
A patch that fixes these issues is available at [2] or as r47867 in branch svn://svn.zabbix.com/branches/dev/ZBX-8582.
[1] https://support.zabbix.com/browse/ZBX-8582
[2] https://github.com/svn2github/zabbix/commit/984bd3bec2d6ca5a80104a5574d19b7f4d04f24b
Discussion:
Created zabbix22 tracking bugs for this issue:
Affects: epel-6 [bug 1178879]
Affects: epel-7 [bug 1178881]
---
Created zabbix20 tracking bugs for this issue:
Affects: epel-6 [bug 1178878]
Affects: epel-7 [bug 1178880]
---
zabbix22-2.2.9-1.el7 has been p
Bugzilla
CVE-2014-9450 zabbix22: zabbix: SQL injection in chart_bar.php [epel-6]
bugzilla·2015-01-05·CVSS 7.5
CVE-2014-9450 [HIGH] CVE-2014-9450 zabbix22: zabbix: SQL injection in chart_bar.php [epel-6]
CVE-2014-9450 zabbix22: zabbix: SQL injection in chart_bar.php [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-6 tracking bug for zabbix22: see blocks bug list for
http://secunia.com/advisories/61554http://www.zabbix.com/rn1.8.22.phphttp://www.zabbix.com/rn2.0.14.phphttp://www.zabbix.com/rn2.2.8.phphttps://support.zabbix.com/browse/ZBX-8582http://secunia.com/advisories/61554http://www.zabbix.com/rn1.8.22.phphttp://www.zabbix.com/rn2.0.14.phphttp://www.zabbix.com/rn2.2.8.phphttps://support.zabbix.com/browse/ZBX-8582
2015-01-02
Published