Package: zabbix-frontend-php
Version: 1:2.2.7+dfsg-2+deb8u1
Severity: grave

Zabbix on Jessie is vulnerable to remote code execution through exploit 
available in [1] (valid zabbix user/password is needed).
I do not find any CVE related to this bug.

[1] https://www.exploit-db.com/exploits/39937/

-- 
Rogerio Bastos
PoP-BA/RNP

Reply via email to