[ZBX-9300] Path revealing vulnerability Created: 2015 Feb 11  Updated: 2019 Dec 10

Status: Open
Project: ZABBIX BUGS AND ISSUES
Component/s: Frontend (F)
Affects Version/s: 2.0.14
Fix Version/s: None

Type: Incident report Priority: Trivial
Reporter: Nitin Assignee: Unassigned
Resolution: Unresolved Votes: 0
Labels: vulnerability
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original Estimate: Not Specified


 Description   

"#1 Request
Payload @PATH@include/
Request GET https://63.243.248.181:443/zabbix/include/
#1 Referer: https://63.243.248.181/zabbix/dashboard.php
#2 Cookie: zbx_sessionid=571b49b70ea77d72d4b259771cea6c7c; ui-tabs-1=0; cb_/zabbix/usergrps.php_parts=0; cb_/zabbix/tr_status.php_parts=0; cb_/zabbix/tem
plates.php_parts=0; cb_/zabbix/sysmaps.php_parts=0; cb_/zabbix/media_types.php_parts=0; cb_/zabbix/hosts.php_parts=0; cb_/zabbix/hostgroups.php_parts= 0; cb_/zabbix/
discoveryconf.php_parts=0; cb_/zabbix/actionconf.php_parts=0; ZBX_CONFIG=a%3A3%3A%7Bs%3A4%3A%22step%22%3Bi%3A0%3Bs%3A5%3A%22agree%22%3Bb
%3A0%3Bs%3A10%3A%22allowed_db%22%3Ba%3A2%3A%7Bs%3A10%3A%22POSTGRESQL%22%3Bs%3A10%3A%22PostgreSQL%22%3Bs%3A7%3A
%22SQLITE3%22%3Bs%3A7%3A%22SQLite3%22%3B %7D%7D; PHPSESSID=uo1jr4pb4runv6v2n6lm7alem3;
#1 Response
comment: The server responded with a verbose error message for this request.
HTTP/1.1 403 Forbidden"


Generated at Thu Apr 25 08:56:18 EEST 2024 using Jira 9.12.4#9120004-sha1:625303b708afdb767e17cb2838290c41888e9ff0.