CVE-2016-4338 | Zabbix up to 2.0.17/2.2.12/3.0.2 Configuration Script userparameter_mysql.conf mysql.size sql injection (EDB-39769 / Nessus ID 95816)
A vulnerability classified as critical has been found in Zabbix up to 2.0.17/2.2.12/3.0.2. Affected is an unknown function of the file userparameter_mysql.conf of the component Configuration Script. The manipulation of the argument mysql.size leads to sql injection.
This vulnerability is traded as CVE-2016-4338. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.