Vulnerabilities > CVE-2006-7191 - Unspecified vulnerability in Ldap Account Manager Ldap Account Manager
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN ldap-account-manager
nessus
Summary
Untrusted search path vulnerability in lamdaemon.pl in LDAP Account Manager (LAM) before 1.0.0 allows local users to gain privileges via a modified PATH that points to a malicious rm program.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-1287.NASL |
description | Two vulnerabilities have been identified in the version of ldap-account-manager shipped with Debian 3.1 (sarge). - CVE-2006-7191 An untrusted PATH vulnerability could allow a local attacker to execute arbitrary code with elevated privileges by providing a malicious rm executable and specifying a PATH environment variable referencing this executable. - CVE-2007-1840 Improper escaping of HTML content could allow an attacker to execute a cross-site scripting attack (XSS) and execute arbitrary code in the victim |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 25176 |
published | 2007-05-10 |
reporter | This script is Copyright (C) 2007-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/25176 |
title | Debian DSA-1287-1 : ldap-account-manager - multiple vulnerabilities |
code |
|
References
- http://lam.cvs.sourceforge.net/lam/lam/lib/lamdaemon.pl
- http://lam.cvs.sourceforge.net/lam/lam/lib/lamdaemon.pl?r1=1.32&r2=1.33
- http://lam.sourceforge.net/changelog/index.htm
- http://secunia.com/advisories/25157
- http://www.securityfocus.com/bid/23857
- http://www.us.debian.org/security/2007/dsa-1287
- http://lam.cvs.sourceforge.net/lam/lam/lib/lamdaemon.pl
- http://www.us.debian.org/security/2007/dsa-1287
- http://www.securityfocus.com/bid/23857
- http://secunia.com/advisories/25157
- http://lam.sourceforge.net/changelog/index.htm
- http://lam.cvs.sourceforge.net/lam/lam/lib/lamdaemon.pl?r1=1.32&r2=1.33