Vyatta –
Linux & Open Source
Alternative to Cisco –
Advanced Routing,
Firewall, VPN, QoS..
Free Download ->
|
|
| |
|
| |
ldap-account-manager: privilege escalation, possible cross-site scripting
| Package(s): | ldap-account-manager |
CVE #(s): | CVE-2006-7191
CVE-2007-1840
|
| Created: | May 7, 2007 |
Updated: | May 9, 2007 |
| Description: |
An untrusted search path vulnerability in lamdaemon.pl in LDAP Account
Manager (LAM) before 1.0.0 allows local users to gain privileges via a
modified PATH that points to a malicious rm program. (CVE-2006-7191)
lib/modules.inc in LDAP Account Manager (LAM) before 1.3.0 does not escape
HTML special characters in LDAP data, which allows remote attackers to have
an unknown impact, probably cross-site scripting (XSS). (CVE-2007-1840) |
| Alerts: |
|
( Log in to post comments)
|
|
|