← Vulnerability feed

Vulnerability record · CVE-2016-4338 · published 23 January 2017

CVE-2016-4338: Zabbix sql injection vulnerability

Zabbix · Zabbix

The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x before 2.2.13, and 3.0.x before 3.0.3, when used with a shell other than bash, allows context-dependent attackers to execute arbitrary code or SQL commands via the mysql.size parameter.

8.1 CVSS 3.0 High EPSS 21% · top 2.5% CWE-89 · SQL injection
8.1CVSS 3.0 base score, v2 6.8
21%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x before 2.2.13, and 3.0.x before 3.0.3, when used with a shell other than bash, allows context-dependent attackers to execute arbitrary code or SQL commands via the mysql.size parameter.

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/136898/Zabbix-Agent-3.0.1-mysql.size-Shell-Command-Injection.html ExploitThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2016/May/9 ExploitThird Party AdvisoryVDB Entry
http://www.securityfocus.com/archive/1/538258/100/0/threaded
http://www.securityfocus.com/bid/89631 Third Party AdvisoryVDB Entry
https://security.gentoo.org/glsa/201612-42 Third Party AdvisoryVDB Entry
https://support.zabbix.com/browse/ZBX-10741 ExploitPatchVendor Advisory
https://www.exploit-db.com/exploits/39769/ ExploitThird Party AdvisoryVDB Entry
https://www.zabbix.com/documentation/2.0/manual/introduction/whatsnew2018#miscellaneous_improvements Vendor Advisory
https://www.zabbix.com/documentation/2.2/manual/introduction/whatsnew2213#miscellaneous_improvements Vendor Advisory
https://www.zabbix.com/documentation/3.0/manual/introduction/whatsnew303#miscellaneous_improvements Vendor Advisory
http://packetstormsecurity.com/files/136898/Zabbix-Agent-3.0.1-mysql.size-Shell-Command-Injection.html ExploitThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2016/May/9 ExploitThird Party AdvisoryVDB Entry
http://www.securityfocus.com/archive/1/538258/100/0/threaded
http://www.securityfocus.com/bid/89631 Third Party AdvisoryVDB Entry
https://security.gentoo.org/glsa/201612-42 Third Party AdvisoryVDB Entry
https://support.zabbix.com/browse/ZBX-10741 ExploitPatchVendor Advisory
https://www.exploit-db.com/exploits/39769/ ExploitThird Party AdvisoryVDB Entry
https://www.zabbix.com/documentation/2.0/manual/introduction/whatsnew2018#miscellaneous_improvements Vendor Advisory
https://www.zabbix.com/documentation/2.2/manual/introduction/whatsnew2213#miscellaneous_improvements Vendor Advisory
https://www.zabbix.com/documentation/3.0/manual/introduction/whatsnew303#miscellaneous_improvements Vendor Advisory

Track CVE-2016-4338 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-23131Zabbix Frontend SAML SSO authentication bypass via session spoofingZabbix Frontend fails to verify the user login stored in the session when SAML SSO authentication is enabled, allowing session data to be modified. A…KEVEPSS 96%analysed5.3CVE-2022-23134Zabbix Frontend setup.php improper access control allows unauthenticated config changeAfter initial setup, some steps of Zabbix Frontend's setup.php remain reachable by unauthenticated users rather than only super-administrators. An at…KEVEPSS 95%analysed10.0CVE-2007-0640Zabbix vulnerabilityBuffer overflow in ZABBIX before 1.1.5 has unknown impact and attack vectors related to "SNMP IP addresses."EPSS 2.0%9.9CVE-2024-42327Zabbix frontend SQL injection in CUser addRelatedObjectsThe CUser.addRelatedObjects function in the Zabbix frontend contains an SQL injection reachable through the CUser.get API call. Any account with API …EPSS 79%analysed9.8CVE-2022-43516Microsoft windows firewall vulnerabilityA Firewall Rule which allows all incoming TCP connections to all programs from any source and to all ports is created in Windows Firewall after Zabbi…EPSS 0.95%9.8CVE-2020-11800Zabbix vulnerabilityZabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code.EPSS 9.2%9.8CVE-2013-3738Zabbix improper input validation vulnerabilityA File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, which could let a remote mali…EPSS 3.1%9.8CVE-2013-5743Zabbix SQL injection in multiple componentsZabbix versions 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7 contain multiple SQL injection vulnerabilities. The record does…EPSS 80%analysed

Source: NIST National Vulnerability Database (record CVE-2016-4338), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.