Vulnerability record · CVE-2016-10134 · published 17 February 2017
CVE-2016-10134: Zabbix latest.php SQL injection via toggle_ids parameter
Zabbix · Zabbix
Zabbix before 2.2.14 and 3.0 before 3.0.4 fails to sanitize the toggle_ids array parameter in latest.php, allowing SQL injection. Because the endpoint is reachable without authentication, an unauthenticated remote attacker can inject arbitrary SQL into the backend database.
Description
SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote SQL injection with CVSS 9.8 and very high EPSS, with public exploit references, makes this an urgent patch target.
What it is
Zabbix before 2.2.14 and 3.0 before 3.0.4 fails to sanitize the toggle_ids array parameter in latest.php, allowing SQL injection. Because the endpoint is reachable without authentication, an unauthenticated remote attacker can inject arbitrary SQL into the backend database.
Impact
An attacker can execute arbitrary SQL commands, enabling theft or modification of monitoring data and potentially full compromise of the Zabbix database and its host.
Attack surface
Reached over the network through the latest.php HTTP endpoint using the toggle_ids array parameter. The CVSS vector shows no privileges or user interaction required, so it is unauthenticated and remotely triggerable.
Exploitation
Not listed in CISA KEV, but EPSS is 0.834 (99.7th percentile) and the vendor advisory ZBX-11023 is tagged Exploit and Patch, indicating public exploit material exists.
What to do
- Upgrade Zabbix to 2.2.14, 3.0.4 or later; apply the vendor patch referenced in ZBX-11023.
- Apply the Debian security update DSA-3802 if running the packaged version.
- Restrict network access to the Zabbix web frontend to trusted management networks.
- Review database accounts used by Zabbix for least privilege and monitor for unexpected queries.
Detection
- Inspect web server and Zabbix logs for requests to latest.php with unusual or malformed toggle_ids array values.
- Enable and review database query logging for anomalous SQL originating from the Zabbix frontend.
- Alert on SQL error responses or unexpected database errors tied to latest.php requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-10134 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-10134), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.