Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2009-4499

EPSS 0.24% · P48
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2009-4499

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
SQL injection vulnerability in the get_history_lastid function in the nodewatcher component in Zabbix Server before 1.6.8 allows remote attackers to execute arbitrary SQL commands via a crafted request, possibly related to the send_history_last_id function in zabbix_server/trapper/nodehistory.c.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Zabbix 'get_history_lastid()' SQL注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Zabbix是一个基于WEB界面的提供分布式系统监视以及网络监视功能的企业级的开源解决方案。 Zabbix Server的nodewatcher组件中的get_history_lastid函数中存在SQL注入漏洞。远程攻击者可以借助一个与zabbix_server/trapper/nodehistory.c中的send_history_last_id函数有关的特制请求,导致执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2009-4499

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2009-4499

登录查看更多情报信息。

Same Patch Batch · n/a · 2009-12-31 · 29 CVEs total

CVE-2009-4526Drupal Printer e-mail和PDF version模块安全绕过漏洞
CVE-2009-4502Zabbix Agent NET_TCP_LISTEN函数权限许可和安全绕过漏洞
CVE-2009-4501Zabbix Server 'str.c' zbx_get_next_field函数拒绝服务漏洞
CVE-2009-4500zabbix 'trapper.c' 空指针拒绝服务漏洞
CVE-2009-4498Zabbix 操作系统命令注入漏洞
CVE-2009-4535valenok mongoose 信息泄露漏洞
CVE-2009-4534Drupal FAQ Ask模块URI开放重定向漏洞
CVE-2009-4533Drupal Webform模块未明会话变量漏洞
CVE-2009-4532Drupal Webform模块跨站脚本攻击漏洞
CVE-2009-4531jazu100 httpdx URI信息泄露漏洞
CVE-2009-4530valenok mongoose 附录::$DATA到URI信息泄露漏洞
CVE-2009-4529Intervations NaviCOPA Web Server HTTP请求源码泄露漏洞
CVE-2009-4528Drupal Organic Groups Vocabulary 模块未授权访问漏洞
CVE-2009-4527Niif Shibboleth验证模块身份认证绕过漏洞
CVE-2009-4512Indymedia oscailt 'index.php'目录遍历漏洞
CVE-2009-4525Drupal Printer e-mail和PDF version 模块特制数据HTML注入漏洞
CVE-2009-4524Drupal RealName 模块跨站脚本攻击漏洞
CVE-2009-4523Zainu 'index.php' SearchSong跨站脚本攻击漏洞
CVE-2009-4522bloofoxCMS 'index.php' search跨站脚本攻击漏洞
CVE-2009-4521Eclipse Business Intelligence和Reporting Tools birt-viewer/run跨站脚本攻击漏洞

Showing top 20 of 29 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2009-4499

No comments yet


Leave a comment