Zabbix before 1.8.6 allows remote attackers to obtain sensitive information via an invalid srcfld2 parameter to popup.php, which reveals the installation path in an error message.
https://support.zabbix.com/browse/ZBX-3840
https://exchange.xforce.ibmcloud.com/vulnerabilities/69377
http://www.zabbix.com/rn1.8.6.php
Source: Mitre, NVD
Published: 2011-08-19
Updated: 2024-11-21
Base Score: 5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N
Severity: Medium
Base Score: 5.3
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N