{"id":"CVE-2011-3264","details":"Zabbix before 1.8.6 allows remote attackers to obtain sensitive information via an invalid srcfld2 parameter to popup.php, which reveals the installation path in an error message.","modified":"2026-04-10T03:41:57.480998Z","published":"2011-08-19T21:55:02Z","references":[{"type":"FIX","url":"http://www.zabbix.com/rn1.8.6.php"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/69377"},{"type":"WEB","url":"https://support.zabbix.com/browse/ZBX-3840"}],"schema_version":"1.7.5"}