First published: Thu Dec 05 2019(Updated: )
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, add_value_form, and dn parameters to cmd.php.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ldap-account-manager Ldap Account Manager | =3.6 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Fedoraproject Fedora | =16 | |
Fedoraproject Fedora | =17 | |
Fedoraproject Fedora | =18 | |
debian/ldap-account-manager | 8.0.1-0+deb11u1 8.3-1 | |
debian/phpldapadmin | 1.2.6.3-0.3 1.2.6.6-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2012-1115 is categorized as medium with a score of 6.1.
To fix CVE-2012-1115, update LDAP Account Manager to the latest version or apply available patches.
CVE-2012-1115 affects LDAP Account Manager Pro version 3.6 as well as specific versions of Debian and Fedora.
CVE-2012-1115 is a Cross-Site Scripting (XSS) vulnerability.
The vulnerability in CVE-2012-1115 can be exploited through the export, add_value_form, and dn parameters to cmd.php.