CVE-2011-2904: XSS
A vulnerability was reported [1],[2] in Zabbix where input passed to the "backurl" parameter in acknow.php is improperly sanitized before being returned to the user. This could be used to facilitate a cross-site scripting attack. This flaw is fixed in Zabbix 1.8.6 [3].
[1] http://secunia.com/advisories/45502 [2] https://support.zabbix.com/browse/ZBX-3835 [3] http://www.zabbix.com/rn1.8.6.php
Other sources
Cross-site scripting (XSS) vulnerability in acknow.php in Zabbix before 1.8.6 allows remote attackers to inject arbitrary web script or HTML via the backurl parameter.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2904?
CVE-2011-2904 has been classified with a medium severity level due to its potential to facilitate cross-site scripting attacks.
How do I fix CVE-2011-2904?
To remediate CVE-2011-2904, upgrade Zabbix to version 1.8.6 or later.
What software versions are affected by CVE-2011-2904?
CVE-2011-2904 affects various versions of Zabbix including but not limited to 1.1, 1.4.x, 1.5.x, and up to 1.8.5.
What type of vulnerability is CVE-2011-2904?
CVE-2011-2904 is a cross-site scripting (XSS) vulnerability caused by improper input sanitization.
What impact can CVE-2011-2904 have on users?
Exploitation of CVE-2011-2904 can lead to malicious scripts being executed in the context of the user's browser, compromising user data security.