Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown
CVE-2013-7484
Disclosure Date: November 30, 2019 (last updated November 27, 2024)
Zabbix before 5.0 represents passwords in the users table with unsalted MD5.
0
Attacker Value
Unknown
CVE-2019-15132
Disclosure Date: August 17, 2019 (last updated November 27, 2024)
Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is possible to enumerate application usernames based on the variability of server responses (e.g., the "Login name or password is incorrect" and "No permissions for system access" messages, or just blocking for a number of seconds). This affects both api_jsonrpc.php and index.php.
0