peter bassill · operator
$ cve CVE-2010-0712 JSON

CVE-2010-0712 EXPLOIT

6.5
MEDIUM · CVSS 2.0 · EPSS 2% (pctl 80)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in zport/dmd/Events/getJSONEventsInfo in Zenoss 2.3.3, and other versions before 2.5, allow remote authenticated users to execute arbitrary SQL commands via the (1) severity, (2) state, (3) filter, (4) offset, and (5) count parameters.

Scoring

CVSS6.5 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS1.98% — more likely to be exploited than 80% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2010-02-26
Last modified2026-06-16

Affected (1)

VendorProduct
zenosszenoss

Public exploits

SourceTitleDate
exploit-dbZenoss 2.3.3 - Multiple SQL Injections2010-01-14

References

→ the Explorer  ·  watch your stack  ·  NVD