Zabbix 2.0.5 allows remote authenticated users to discover the LDAP bind password by leveraging management-console access and reading the ldap_bind_password value in the HTML source code.
References
Configurations
History
No history.
Information
Published : 2013-10-01 03:48
Updated : 2014-05-10 03:58
NVD link : CVE-2013-5572
Mitre link : CVE-2013-5572
CVE.ORG link : CVE-2013-5572
JSON object : View
Products Affected
zabbix
- zabbix
CWE
CWE-264
Permissions, Privileges, and Access Controls