Show filters
13 Total Results
Displaying 11-13 of 13
Sort by:
Attacker Value
Unknown

CVE-2013-4453

Disclosure Date: November 05, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in templates/login.php in LDAP Account Manager (LAM) 4.3 and 4.2.1 allows remote attackers to inject arbitrary web script or HTML via the language parameter.
0
Attacker Value
Unknown

CVE-2007-1840

Disclosure Date: April 03, 2007 (last updated October 04, 2023)
lib/modules.inc in LDAP Account Manager (LAM) before 1.3.0 does not escape HTML special characters in LDAP data, which allows remote attackers to have an unknown impact, probably cross-site scripting (XSS).
0
Attacker Value
Unknown

CVE-2006-7191

Disclosure Date: April 03, 2007 (last updated October 04, 2023)
Untrusted search path vulnerability in lamdaemon.pl in LDAP Account Manager (LAM) before 1.0.0 allows local users to gain privileges via a modified PATH that points to a malicious rm program.
0