CVE-2016-4338 | Zabbix up to 2.0.17/2.2.12/3.0.2 Configuration Script userparameter_mysql.conf mysql.size sql injection (EDB-39769 / Nessus ID 95816)
A vulnerability, which was classified as critical, has been found in Zabbix up to 2.0.17/2.2.12/3.0.2. Affected is an unknown function of the file userparameter_mysql.conf of the component Configuration Script. The manipulation of the argument mysql.size leads to sql injection.
This vulnerability is documented as CVE-2016-4338. The attack can be initiated remotely. Additionally, an exploit exists.
It is advisable to upgrade the affected component.