Back to Database
Status published
Medium
CVE-2011-3265
popup.php in Zabbix before 1.8.7 allows remote attackers to read...
Vulnerability Description
popup.php in Zabbix before 1.8.7 allows remote attackers to read the contents of arbitrary database tables via a modified srctbl parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-3265
Credits & Attribution
No credits recorded in the NVD database.
References
- https://support.zabbix.com/browse/ZBX-3840
- http://lists.fedoraproject.org/pipermail/package-announce/2011-September/066092.html
- http://www.securityfocus.com/bid/49277
- https://support.zabbix.com/browse/ZBX-3955
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69376
- http://lists.fedoraproject.org/pipermail/package-announce/2011-September/066110.html
More from zabbix
View All →CVE-2022-22704
The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows...
Critical
9.8
CVE-2021-46088
Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable...
High
7.2
CVE-2021-27927
In Zabbix from 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x...
High
8.8
CVE-2020-15803
Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before...
Medium
6.1
CVE-2020-11800
Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows...
Critical
9
Affected Vendor
zabbix
View all reports →Affected Software
zabbix
Vulnerable Versions:
0, 1.1, 1.1.1, 1.1.2, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.3, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.8, 1.4.2, 1.4.3, 1.4.4, 1.4.5, 1.4.6, 1.5, 1.5.1, 1.5.2, 1.5.3, 1.5.4, 1.6, 1.6.1, 1.6.2, 1.6.3, 1.6.4, 1.6.5, 1.6.6, 1.6.7, 1.6.8, 1.6.9, 1.7, 1.7.1, 1.7.2, 1.7.3, 1.7.4, 1.8, 1.8.1, 1.8.2, 1.8.3, 1.8.4, 1.8.5, 1.8.6
Timeline
Official Publish:
August 19th, 2011
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.