CVE-2009-4498
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 32%
from disclosure to weapon0 days
Published on NVDDec 31
1st PoCDec 14
metasploitSep 10
exploitation probability
32%top 2% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
The node_process_command function in Zabbix Server before 1.8 allows remote attackers to execute arbitrary commands via a crafted request.
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/20796unverifiedexploitdbwww.exploit-db.com/exploits/10432unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.