Zabbix 3.0.3, vulnerable to CVE-2016-10134: the toggle_ids array of latest.php and the profileIdx2 parameter of jsrpc.php reach SQL queries unescaped, so the guest account (or no session for jsrpc.php) runs error-based SQL injection.
Pas commencéDockercommit c9254eex86_64 · aarch64Secret
Exploit CVE-2016-10134 to inject SQL into Zabbix and read the flag from the flags table of its database.
Le brief de ce lab se trouve dans son dépôt.