CVE-2024-22120 ToolKit

Cr1xXyu

Active member
Member
Joined
1 yrs. 10 mth. 1 days
Messages
40
Reaction score
1
Wallet
150$
From the Zabbix admin panel, the user can execute pre-created scripts (by default, ping and traceroute).

After the script is executed, the event is recorded in the Audit Log. The event has a field with the client IP. Because it is not sanitized, it results in SQL injection.
Please, Log in or Register to view URLs content!

The script receives an admin session and sends a reverse shell.
 
Top Bottom