The user.login function in Zabbix before 1.8.16 and 2.x before 2.0.5rc1 allows remote attackers to override LDAP configuration via the cnf parameter.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Zabbix | Zabbix | * | 1.8.15 (including) |
Zabbix | Zabbix | 2.0.0 (including) | 2.0.0 (including) |
Zabbix | Zabbix | 2.0.1 (including) | 2.0.1 (including) |
Zabbix | Zabbix | 2.0.2 (including) | 2.0.2 (including) |
Zabbix | Zabbix | 2.0.3 (including) | 2.0.3 (including) |
Zabbix | Zabbix | 2.0.4 (including) | 2.0.4 (including) |
Zabbix | Ubuntu | hardy | * |
Zabbix | Ubuntu | lucid | * |
Zabbix | Ubuntu | oneiric | * |
Zabbix | Ubuntu | precise | * |
Zabbix | Ubuntu | quantal | * |
Zabbix | Ubuntu | raring | * |
Zabbix | Ubuntu | saucy | * |
Zabbix | Ubuntu | upstream | * |