Multiple SQL injection vulnerabilities in zport/dmd/Events/getJSONEventsInfo in Zenoss 2.3.3, and other versions before 2.5, allow remote authenticated users to execute arbitrary SQL commands via the (1) severity, (2) state, (3) filter, (4) offset, and (5) count parameters.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2010-02-26T17:03:00

Updated: 2024-08-07T00:59:38.376Z

Reserved: 2010-02-26T00:00:00

Link: CVE-2010-0712

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2010-02-26T17:30:01.437

Modified: 2017-08-17T01:32:05.057

Link: CVE-2010-0712

cve-icon Redhat

No data.