popup.php in Zabbix before 1.8.7 allows remote attackers to read the contents of arbitrary database tables via a modified srctbl parameter.
https://support.zabbix.com/browse/ZBX-3955
https://support.zabbix.com/browse/ZBX-3840
https://exchange.xforce.ibmcloud.com/vulnerabilities/69376
http://www.securityfocus.com/bid/49277
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/066110.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/066092.html