Vulnerabilities (CVE)

Filtered by vendor Ldap Account Manager Subscribe
Filtered by product Ldap Account Manager
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-1840 1 Ldap Account Manager 1 Ldap Account Manager 2024-02-04 4.3 MEDIUM N/A
lib/modules.inc in LDAP Account Manager (LAM) before 1.3.0 does not escape HTML special characters in LDAP data, which allows remote attackers to have an unknown impact, probably cross-site scripting (XSS).
CVE-2006-7191 1 Ldap Account Manager 1 Ldap Account Manager 2024-02-04 7.2 HIGH N/A
Untrusted search path vulnerability in lamdaemon.pl in LDAP Account Manager (LAM) before 1.0.0 allows local users to gain privileges via a modified PATH that points to a malicious rm program.