### [CVE-2016-10134](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10134) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php. ### POC #### Reference - https://code610.blogspot.com/2017/10/zbx-11023-quick-autopsy.html #### Github - https://github.com/0ps/pocassistdb - https://github.com/1120362990/vulnerability-list - https://github.com/189569400/Meppo - https://github.com/1N3/1N3 - https://github.com/1N3/Exploits - https://github.com/ARPSyndicate/cvemon - https://github.com/ARPSyndicate/kenzer-templates - https://github.com/Awrrays/FrameVul - https://github.com/CLincat/vulcat - https://github.com/HimmelAward/Goby_POC - https://github.com/SexyBeast233/SecBooks - https://github.com/TesterCC/exp_poc_library - https://github.com/Threekiii/Awesome-POC - https://github.com/Threekiii/Vulhub-Reproduce - https://github.com/WingsSec/Meppo - https://github.com/Z0fhack/Goby_POC - https://github.com/amcai/myscan - https://github.com/bakery312/Vulhub-Reproduce - https://github.com/bigblackhat/oFx - https://github.com/dravenww/curated-article - https://github.com/jweny/pocassistdb - https://github.com/maya6/-scan- - https://github.com/woods-sega/woodswiki