Ad Widget

Collapse

SQL Injection - Zabbix 3.4.15

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • amirreza.najafi@atos.net
    Junior Member
    • Oct 2019
    • 1

    #1

    SQL Injection - Zabbix 3.4.15

    Hi All,

    After scan with some vulnerability scan Application we see this message. would you please help us how we can remediate this issue or this is just a false positive report.
    CGI Generic SQL Injection (blind)

    + The following resources may be vulnerable to blind SQL injection : + The 'autologin' parameter of the /zabbix/index.php CGI : /zabbix/index.php?password=&name=&autologin=1zz&name=&auto login=1yy -------- output -------- <div class="msg-bad">Page received incorrect data<div class="msg-details "><span class="link-action" onclick="javascript: showHide($(this).next(' .msg-details-border'));">Details</span><ul class="msg-details-border"><l i>Field &quot;Username&quot; must be missing.</li></ul></div><butt [...] <html> <head> -------- vs -------- <div class="msg-bad">Page received incorrect data<div class="msg-details "><span class="link-action" onclick="javascript: showHide($(this).next(' .msg-details-border'));">Details</span><ul class="msg-details-border"><l i>Field &quot;Username&quot; must be missing.</li><li>Field &quot; [...] <html> <head> ------------------------

Working...