Vulnerabilities > Zabbix > Zabbix > 1.6.9
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2011-08-19 | CVE-2011-3264 | Information Exposure vulnerability in Zabbix Zabbix before 1.8.6 allows remote attackers to obtain sensitive information via an invalid srcfld2 parameter to popup.php, which reveals the installation path in an error message. | 5.0 |
2011-08-19 | CVE-2011-3263 | Resource Management Errors vulnerability in Zabbix zabbix_agentd in Zabbix before 1.8.6 and 1.9.x before 1.9.4 allows context-dependent attackers to cause a denial of service (CPU consumption) by executing the vfs.file.cksum command for a special device, as demonstrated by the /dev/urandom device. | 5.0 |
2011-08-19 | CVE-2011-2904 | Cross-Site Scripting vulnerability in Zabbix Cross-site scripting (XSS) vulnerability in acknow.php in Zabbix before 1.8.6 allows remote attackers to inject arbitrary web script or HTML via the backurl parameter. | 4.3 |
2009-12-31 | CVE-2009-4498 | OS Command Injection vulnerability in Zabbix The node_process_command function in Zabbix Server before 1.8 allows remote attackers to execute arbitrary commands via a crafted request. | 6.8 |