Version detection

The Zabbix version is both easy to obtain and decisive, because the SQL-injection and remote-code-execution chains are version-specific. The API exposes it without authentication through apiinfo.version (one of the few unauthenticated methods), and the web UI shows it in the login-page and footer "Zabbix x.y.z" string. Reading it first tells you whether the instance is in range for a known pre-authentication exploit, and which authentication and code-execution behaviours to expect (defaults, API shape, and script handling changed across major versions).

bash
Z=https://<target>/zabbix/api_jsonrpc.php
# unauthenticated version via the API
curl -sk $Z -H 'Content-Type: application/json-rpc' \
  -d '{"jsonrpc":"2.0","method":"apiinfo.version","params":{},"id":1}'
# version from the web UI footer/login page
curl -sk https://<target>/zabbix/index.php | grep -ioE 'Zabbix [0-9]+\.[0-9]+\.[0-9]+'

Exploitation notes#

  • apiinfo.version answers without credentials, so the version is free; it maps directly to the applicable known server exploits and SQLi chains.
  • Major versions differ in defaults and features (guest access, API tokens, script execution model), so the version also selects which authentication and code-execution techniques apply.
  • The footer string corroborates the API result and works when the API path is filtered; both are pre-auth.
  • Feed the version into exploit selection, then enumerate users and hosts once you have access.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more