CVE-2012-3435
EPSS 1.8%zabbix - SQL injection
Published: 8/15/2012Modified: 4/28/2026
Also known as:DEBIAN-CVE-2012-3435
Description
SQL injection vulnerability in frontends/php/popup_bitem.php in Zabbix 1.8.15rc1 and earlier, and 2.x before 2.0.2rc1, allows remote attackers to execute arbitrary SQL commands via the itemid parameter.
Affected packages (2)
- Debian/zabbixfrom 0, < 1:2.0.2+dfsg-1
- Debian/zabbixfrom 0, < 1:1.8.2-1squeeze4