Candidate: CVE-2011-3264 PublicDate: 2011-08-19 21:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3264 Description: Zabbix before 1.8.6 allows remote attackers to obtain sensitive information via an invalid srcfld2 parameter to popup.php, which reveals the installation path in an error message. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_zabbix: upstream_zabbix: released (1.8.6) hardy_zabbix: ignored (reached end-of-life) lucid_zabbix: ignored (reached end-of-life) maverick_zabbix: ignored (reached end-of-life) natty_zabbix: ignored (reached end-of-life) oneiric_zabbix: ignored (reached end-of-life) precise_zabbix: not-affected (1:1.8.6-1) quantal_zabbix: not-affected (1:1.8.6-1) raring_zabbix: not-affected (1:1.8.6-1) saucy_zabbix: not-affected (1:1.8.6-1) devel_zabbix: not-affected (1:1.8.6-1)