CVE-2019-17382: Zabbix <=4.4 - Authentication Bypass

CVE-2019-17382: Zabbix <=4.4 - Authentication Bypass-渗透云记 - 专注于网络安全与技术分享
CVE-2019-17382: Zabbix <=4.4 - Authentication Bypass
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2019-17382: Zabbix <=4.4 – Authentication Bypass

漏洞描述

Zabbix through 4.4 is susceptible to an authentication bypass vulnerability via zabbix.php?action=dashboard.view&dashboardid=1. An attacker can bypass the login page and access the dashboard page, and then create a Dashboard, Report, Screen, or Map without any Username/Password (i.e., anonymously). All created elements (Dashboard/Report/Screen/Map) are accessible by other users and by an admin.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享