SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  Zabbix Server setup.php Authentication Bypass

Category: WEB-ATTACKS      

After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.

References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1990


Relevant Information