CVE-2011-3265: Infoleak
popup.php in Zabbix before 1.8.7 allows remote attackers to read the contents of arbitrary database tables via a modified srctbl parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3265?
CVE-2011-3265 is considered a medium severity vulnerability due to its potential to expose sensitive database information to attackers.
How do I fix CVE-2011-3265?
To fix CVE-2011-3265, upgrade Zabbix to version 1.8.7 or later, which addresses this vulnerability.
Which versions of Zabbix are affected by CVE-2011-3265?
CVE-2011-3265 affects Zabbix versions prior to 1.8.7, including versions 1.1, 1.4.x, 1.5.x, 1.6.x, 1.7.x, and 1.8.0 to 1.8.6.
What type of attack can exploit CVE-2011-3265?
CVE-2011-3265 can be exploited through a remote attack that manipulates the 'srctbl' parameter to read arbitrary database tables.
Is there a workaround for CVE-2011-3265?
A potential workaround for CVE-2011-3265 is to restrict access to the vulnerable parameter until a patch or upgrade can be applied.