Vulnerabilities > CVE-2007-1840 - HTML Injection vulnerability in LDAP Account Manager
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE Summary
lib/modules.inc in LDAP Account Manager (LAM) before 1.3.0 does not escape HTML special characters in LDAP data, which allows remote attackers to have an unknown impact, probably cross-site scripting (XSS).
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-1287.NASL |
description | Two vulnerabilities have been identified in the version of ldap-account-manager shipped with Debian 3.1 (sarge). - CVE-2006-7191 An untrusted PATH vulnerability could allow a local attacker to execute arbitrary code with elevated privileges by providing a malicious rm executable and specifying a PATH environment variable referencing this executable. - CVE-2007-1840 Improper escaping of HTML content could allow an attacker to execute a cross-site scripting attack (XSS) and execute arbitrary code in the victim |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 25176 |
published | 2007-05-10 |
reporter | This script is Copyright (C) 2007-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/25176 |
title | Debian DSA-1287-1 : ldap-account-manager - multiple vulnerabilities |
code |
|
References
- http://lam.cvs.sourceforge.net/lam/lam/lib/modules.inc?r1=1.173&r2=1.174
- http://lam.sourceforge.net/changelog/index.htm
- http://secunia.com/advisories/24687
- http://secunia.com/advisories/25157
- http://www.securityfocus.com/bid/23190
- http://www.us.debian.org/security/2007/dsa-1287
- http://www.vupen.com/english/advisories/2007/1149
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33307