CVE-2011-3265
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
19/08/2011
Last modified:
11/04/2025
Description
popup.php in Zabbix before 1.8.7 allows remote attackers to read the contents of arbitrary database tables via a modified srctbl parameter.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* | 1.8.6 (including) | |
cpe:2.3:a:zabbix:zabbix:1.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:zabbix:zabbix:1.1:beta10:*:*:*:*:*:* | ||
cpe:2.3:a:zabbix:zabbix:1.1:beta11:*:*:*:*:*:* | ||
cpe:2.3:a:zabbix:zabbix:1.1:beta12:*:*:*:*:*:* | ||
cpe:2.3:a:zabbix:zabbix:1.1:beta2:*:*:*:*:*:* | ||
cpe:2.3:a:zabbix:zabbix:1.1:beta3:*:*:*:*:*:* | ||
cpe:2.3:a:zabbix:zabbix:1.1:beta4:*:*:*:*:*:* | ||
cpe:2.3:a:zabbix:zabbix:1.1:beta5:*:*:*:*:*:* | ||
cpe:2.3:a:zabbix:zabbix:1.1:beta6:*:*:*:*:*:* | ||
cpe:2.3:a:zabbix:zabbix:1.1:beta7:*:*:*:*:*:* | ||
cpe:2.3:a:zabbix:zabbix:1.1:beta8:*:*:*:*:*:* | ||
cpe:2.3:a:zabbix:zabbix:1.1:beta9:*:*:*:*:*:* | ||
cpe:2.3:a:zabbix:zabbix:1.1.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:zabbix:zabbix:1.1.2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://lists.fedoraproject.org/pipermail/package-announce/2011-September/066092.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-September/066110.html
- http://www.securityfocus.com/bid/49277
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69376
- https://support.zabbix.com/browse/ZBX-3840
- https://support.zabbix.com/browse/ZBX-3955
- http://lists.fedoraproject.org/pipermail/package-announce/2011-September/066092.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-September/066110.html
- http://www.securityfocus.com/bid/49277
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69376
- https://support.zabbix.com/browse/ZBX-3840
- https://support.zabbix.com/browse/ZBX-3955