Zabbix 2.0.5 allows remote authenticated users to discover the LDAP bind password by leveraging management-console access and reading the ldap_bind_password value in the HTML source code.
327557842dd7782175a33303962605165ac096158c48e68bfc6b59817ebd0933
Gentoo Linux Security Advisory 201311-15 - Multiple vulnerabilities have been found in Zabbix, possibly leading to SQL injection attacks, Denial of Service, or information disclosure. Versions less than 2.0.9_rc1-r2 are affected.
376284ead2ebc1de7d71b4043ed1c195b1d07fa77b9a865731ec3db09ef944b1
Zabbix version 2.0.5 suffers from an issue where it allows for the disclosure of a user's password.
cf632cf260f0dd10243a64e66e97a8eb0ca481c0cc6b35ff2633b0cd564cacf9