Vulnerability Description
A File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, which could let a remote malicious user execute arbitrary code.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zabbix | Zabbix | 2.0.6 |
Related Weaknesses (CWE)
References
- http://support.zabbix.com/browse/ZBX-6652ExploitPatchVendor Advisory
- http://support.zabbix.com/browse/ZBX-6652ExploitPatchVendor Advisory
FAQ
What is CVE-2013-3738?
CVE-2013-3738 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, which could let a remote malicious user execute arbitrary code.
How severe is CVE-2013-3738?
CVE-2013-3738 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2013-3738?
Check the references section above for vendor advisories and patch information. Affected products include: Zabbix Zabbix.