CVE-2012-1115: XSS
Published Dec 5, 2019
·Updated
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, addvalueform, and dn parameters to cmd.php.
Affected Software
8 affected componentsFixes available
ldap-account-manager LDAP Account Manager=3.6
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Fedoraproject Fedora=16
Fedoraproject Fedora=17
Fedoraproject Fedora=18
debian/ldap-account-manager
8.0.1-0+deb11u18.3-19.0-1
debian/phpldapadmin
1.2.6.3-0.3+deb12u11.2.6.7-4
Event History
Dec 5, 2019
CVE Published
via MITRE·08:20 PM
Data Sourced
via MITRE·08:20 PM
DescriptionWeakness
Feb 18, 2026
Data Sourced
via Debian·01:03 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2012-1115?
The severity of CVE-2012-1115 is categorized as medium with a score of 6.1.
2
How do I fix CVE-2012-1115?
To fix CVE-2012-1115, update LDAP Account Manager to the latest version or apply available patches.
3
Which versions are affected by CVE-2012-1115?
CVE-2012-1115 affects LDAP Account Manager Pro version 3.6 as well as specific versions of Debian and Fedora.
4
What type of vulnerability is CVE-2012-1115?
CVE-2012-1115 is a Cross-Site Scripting (XSS) vulnerability.
5
Which components are exploited in CVE-2012-1115?
The vulnerability in CVE-2012-1115 can be exploited through the export, add_value_form, and dn parameters to cmd.php.