CVE-2024-22120: Zabbix Server – Time-Based Blind SQL injection

CVE-2024-22120: Zabbix Server - Time-Based Blind SQL injection-渗透云记 - 专注于网络安全与技术分享
CVE-2024-22120: Zabbix Server – Time-Based Blind SQL injection
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2024-22120: Zabbix Server – Time-Based Blind SQL injection

漏洞描述

The Zabbix server can execute commands for configured scripts. After executing a command, an audit entry is added to the "Audit Log". Due to the "clientip" field not being sanitized, it is possible to inject SQL into "clientip" and exploit a time-based blind SQL injection vulnerability.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享