Zabbix 2.0.5 allows remote authenticated users to discover the LDAP bind password by leveraging management-console access and reading the ldap_bind_password value in the HTML source code.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Zabbix | Zabbix | 2.0.5 (including) | 2.0.5 (including) |
Zabbix | Ubuntu | lucid | * |
Zabbix | Ubuntu | precise | * |
Zabbix | Ubuntu | quantal | * |
Zabbix | Ubuntu | raring | * |
Zabbix | Ubuntu | saucy | * |
Zabbix | Ubuntu | upstream | * |