VYPR
Unrated severityNVD Advisory· Published Apr 6, 2010· Updated Apr 29, 2026

CVE-2010-1277

CVE-2010-1277

Description

SQL injection vulnerability in the user.authenticate method in the API in Zabbix 1.8 before 1.8.2 allows remote attackers to execute arbitrary SQL commands via the user parameter in JSON data to api_jsonrpc.php.

Affected products

2
  • Zabbix/Zabbix2 versions
    cpe:2.3:a:zabbix:zabbix:1.8:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:zabbix:zabbix:1.8:*:*:*:*:*:*:*
    • cpe:2.3:a:zabbix:zabbix:1.8.1:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.