This file is indexed.

/usr/share/zabbix/popup_right.php is in zabbix-frontend-php 1:3.0.12+dfsg-1.

This file is owned by root:root, with mode 0o644.

The actual contents of the file can be viewed below.

  1
  2
  3
  4
  5
  6
  7
  8
  9
 10
 11
 12
 13
 14
 15
 16
 17
 18
 19
 20
 21
 22
 23
 24
 25
 26
 27
 28
 29
 30
 31
 32
 33
 34
 35
 36
 37
 38
 39
 40
 41
 42
 43
 44
 45
 46
 47
 48
 49
 50
 51
 52
 53
 54
 55
 56
 57
 58
 59
 60
 61
 62
 63
 64
 65
 66
 67
 68
 69
 70
 71
 72
 73
 74
 75
 76
 77
 78
 79
 80
 81
 82
 83
 84
 85
 86
 87
 88
 89
 90
 91
 92
 93
 94
 95
 96
 97
 98
 99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
<?php
/*
** Zabbix
** Copyright (C) 2001-2017 Zabbix SIA
**
** This program is free software; you can redistribute it and/or modify
** it under the terms of the GNU General Public License as published by
** the Free Software Foundation; either version 2 of the License, or
** (at your option) any later version.
**
** This program is distributed in the hope that it will be useful,
** but WITHOUT ANY WARRANTY; without even the implied warranty of
** MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
** GNU General Public License for more details.
**
** You should have received a copy of the GNU General Public License
** along with this program; if not, write to the Free Software
** Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA  02110-1301, USA.
**/


require_once dirname(__FILE__).'/include/config.inc.php';

$page['title'] = _('Resource');
$page['file'] = 'popup_right.php';

define('ZBX_PAGE_NO_MENU', 1);

require_once dirname(__FILE__).'/include/page_header.php';

//	VAR					TYPE	OPTIONAL FLAGS	VALIDATION	EXCEPTION
$fields = [
	'dstfrm' =>		[T_ZBX_STR, O_MAND,P_SYS, NOT_EMPTY,	null],
	'permission' =>	[T_ZBX_INT, O_MAND,P_SYS, IN(PERM_DENY.','.PERM_READ.','.PERM_READ_WRITE), null]
];
check_fields($fields);

$dstfrm = getRequest('dstfrm', 0);
$permission = getRequest('permission', PERM_DENY);

/*
 * Display
 */

// host groups
$hostGroupForm = (new CForm())->setId('groups');

$hostGroupTable = (new CTableInfo())
	->setHeader([
		(new CColHeader(
			(new CCheckBox('all_groups'))->onClick('checkAll(this.checked)')
		))->addClass(ZBX_STYLE_CELL_WIDTH),
		_('Name')
	]);

$hostGroups = API::HostGroup()->get([
	'output' => ['groupid', 'name']
]);

order_result($hostGroups, 'name');

foreach ($hostGroups as $hostGroup) {
	$hostGroupTable->addRow([
		(new CCheckBox())
			->setAttribute('data-id', $hostGroup['groupid'])
			->setAttribute('data-name', $hostGroup['name'])
			->setAttribute('data-permission', $permission),
		$hostGroup['name']
	]);
}

$hostGroupTable->setFooter(
	(new CCol(
		(new CButton('select', _('Select')))->onClick('addGroups("'.$dstfrm.'")')
	))
);

$hostGroupForm->addItem($hostGroupTable);

(new CWidget())
	->setTitle(permission2str($permission))
	->addItem($hostGroupForm)
	->show();

?>
<script type="text/javascript">
	function addGroups(formName) {
		var parentDocument = window.opener.document;

		if (!parentDocument) {
			return close_window();
		}

		jQuery('#groups input[type=checkbox]').each(function() {
			var obj = jQuery(this);

			if (obj.attr('name') !== 'all_groups' && obj.prop('checked')) {
				var id = obj.data('id');

				add_variable('input', 'new_right[' + id + '][permission]', obj.data('permission'), formName,
					parentDocument);
				add_variable('input', 'new_right[' + id + '][name]', obj.data('name'), formName, parentDocument);
			}
		});

		parentDocument.forms[formName].submit();

		close_window();
	}

	function checkAll(value) {
		jQuery('#groups input[type=checkbox]').each(function() {
			jQuery(this).prop('checked', value);
		});
	}
</script>
<?php

require_once dirname(__FILE__).'/include/page_footer.php';