vendor:
Zabbix
by:
Pablo González
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Zabbix
Affected Version From: 2.0.5
Affected Version To: 2.0.5
Patch Exists: YES
Related CWE: CVE-2013-5572
CPE: a:zabbix:zabbix
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux (Ubuntu, Suse, CentOS)
2013
ldap_bind_password Zabbix CVE-2013-5572
Zabbix 2.0.5 allows remote authenticated users to discover the LDAP bind password by leveraging management-console access and reading the ldap_bind_password value in the HTML source code.
Mitigation:
Upgrade to the latest version of Zabbix