|
|
| |
|
| |
zabbix: cross-site scripting
| Package(s): | zabbix |
CVE #(s): | CVE-2011-2904
|
| Created: | August 18, 2011 |
Updated: | August 24, 2011 |
| Description: |
From the Red Hat bugzilla:
A vulnerability was reported in Zabbix where input passed to the
"backurl" parameter in acknow.php is improperly sanitized before being returned to the user. This could be used to facilitate a cross-site scripting attack. This flaw is fixed in Zabbix 1.8.6 |
| Alerts: |
|
( Log in to post comments)
|
|
|