Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2011-3264

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2011-3264
Last Modified 06 Sep 2011 11:18:11
Published 19 Aug 2011 05:55:02
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2011-3264

Summary

Zabbix before 1.8.6 allows remote attackers to obtain sensitive information via an invalid srcfld2 parameter to popup.php, which reveals the installation path in an error message.

Vulnerable Systems

Application

  • Zabbix 1.1

  • Zabbix 1.1.1

  • Zabbix 1.1.2

  • Zabbix 1.1.3

  • Zabbix 1.1.4

  • Zabbix 1.1.5

  • Zabbix 1.1.6

  • Zabbix 1.1.7

  • Zabbix 1.3

  • Zabbix 1.3.1

  • Zabbix 1.3.2

  • Zabbix 1.3.3

  • Zabbix 1.3.4

  • Zabbix 1.3.5

  • Zabbix 1.3.6

  • Zabbix 1.3.7

  • Zabbix 1.3.8

  • Zabbix 1.4.2

  • Zabbix 1.4.3

  • Zabbix 1.4.4

  • Zabbix 1.4.5

  • Zabbix 1.4.6

  • Zabbix 1.5

  • Zabbix 1.5.1

  • Zabbix 1.5.2

  • Zabbix 1.5.3

  • Zabbix 1.5.4

  • Zabbix 1.6

  • Zabbix 1.6.1

  • Zabbix 1.6.2

  • Zabbix 1.6.3

  • Zabbix 1.6.4

  • Zabbix 1.6.5

  • Zabbix 1.6.6

  • Zabbix 1.6.7

  • Zabbix 1.6.8

  • Zabbix 1.6.9

  • Zabbix 1.7

  • Zabbix 1.7.1

  • Zabbix 1.7.2

  • Zabbix 1.7.3

  • Zabbix 1.7.4

  • Zabbix 1.8

  • Zabbix 1.8.1

  • Zabbix 1.8.2

  • Zabbix 1.8.3

  • Zabbix 1.8.4

  • Zabbix 1.8.5


References

CONFIRM - http://www.zabbix.com/rn1.8.6.php

CONFIRM - https://support.zabbix.com/browse/ZBX-3840

XF - zabbix-popup-path-dsiclsoure(69377)


Last Updated: 27 May 2016 10:57:15