{"id":"CVE-2010-5049","details":"SQL injection vulnerability in events.php in Zabbix 1.8.1 and earlier allows remote attackers to execute arbitrary SQL commands via the nav_time parameter.","modified":"2026-04-10T03:41:35.756925Z","published":"2011-11-23T01:55:04Z","references":[{"type":"ADVISORY","url":"http://secunia.com/advisories/39119"},{"type":"ADVISORY","url":"http://www.vupen.com/english/advisories/2010/1240"},{"type":"WEB","url":"http://packetstormsecurity.org/1004-exploits/zabbix181-sql.txt"},{"type":"WEB","url":"http://www.securityfocus.com/archive/1/511454/100/0/threaded"},{"type":"WEB","url":"http://www.securityfocus.com/bid/39752"}],"schema_version":"1.7.5"}