Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ldap account manager ldap account manager vulnerabilities and exploits
(subscribe to this query)
383
VMScore
CVE-2018-8763
Roland Gruber Softwareentwicklung LDAP Account Manager prior to 6.3 has XSS via the dn parameter to the templates/3rdParty/pla/htdocs/cmd.php URI or the template parameter to the templates/3rdParty/pla/htdocs/cmd.php?cmd=rename_form URI.
Debian Debian Linux 9.0
Debian Debian Linux 8.0
Debian Debian Linux 7.0
Ldap-account-manager Ldap Account Manager
383
VMScore
CVE-2012-1114
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filter parameter to cmd.php in an export and exporter_id action. and the filteruid parameter to list.php.
Ldap-account-manager Ldap Account Manager 3.6
Debian Debian Linux 8.0
Debian Debian Linux 9.0
Fedoraproject Fedora 16
Fedoraproject Fedora 17
Fedoraproject Fedora 18
383
VMScore
CVE-2012-1115
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, add_value_form, and dn parameters to cmd.php.
Ldap-account-manager Ldap Account Manager 3.6
Debian Debian Linux 8.0
Debian Debian Linux 9.0
Fedoraproject Fedora 16
Fedoraproject Fedora 17
Fedoraproject Fedora 18
NA
CVE-2024-23333
LDAP Account Manager (LAM) is a webfrontend for managing entries stored in an LDAP directory. LAM's log configuration allows to specify arbitrary paths for log files. Prior to version 8.7, an attacker could exploit this by creating a PHP file and cause LAM to log some PHP co...
312
VMScore
CVE-2017-7568
NetApp OnCommand Unified Manager for 7-Mode (core package) versions before 5.2.3 may disclose sensitive LDAP account information to authenticated users when the LDAP authentication configuration is tested via the user interface.
Netapp Oncommand Unified Manager
890
VMScore
CVE-2015-0546
EMC Unified Infrastructure Manager/Provisioning (UIM/P) 4.1 allows remote malicious users to bypass LDAP authentication by providing a valid account name.
Emc Unified Infrastructure Manager\\/provisioning 4.1
668
VMScore
CVE-2017-4976
EMC ESRS Policy Manager before 6.8 contains an undocumented account (OpenDS admin) with a default password. A remote attacker with the knowledge of the default password may login to the system and gain administrator privileges to the local LDAP directory server.
Emc Esrs Policy Manager
694
VMScore
CVE-2013-3415
Cisco Adaptive Security Appliance (ASA) Software 8.4.x prior to 8.4(3) and 8.6.x prior to 8.6(1.3) does not properly manage memory upon an AnyConnect SSL VPN client disconnection, which allows remote malicious users to cause a denial of service (memory consumption, and forwarding...
Cisco Adaptive Security Appliance Software 8.4\\(1.11\\)
Cisco Adaptive Security Appliance Software 8.4\\(2\\)
Cisco Adaptive Security Appliance Software 8.4\\(2.11\\)
Cisco Adaptive Security Appliance Software 8.4\\(1\\)
Cisco Adaptive Security Appliance Software 8.4
Cisco Adaptive Security Appliance Software 8.6\\(1\\)
Cisco Adaptive Security Appliance Software 8.6\\(1.10\\)
Cisco Adaptive Security Appliance Software 8.6
632
VMScore
CVE-2013-5507
The IPsec implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1 prior to 9.1(1.7), when an IPsec VPN tunnel is enabled, allows remote malicious users to cause a denial of service (device reload) via a (1) ICMP or (2) ICMPv6 packet that is improperly handled durin...
Cisco Adaptive Security Appliance Software 9.1
890
VMScore
CVE-2013-5509
The SSL implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0 prior to 9.0(2.6) and 9.1 prior to 9.1(2) allows remote malicious users to bypass authentication, and obtain VPN access or administrative access, via a crafted X.509 client certificate, aka Bug ID CSCu...
Cisco Adaptive Security Appliance Software 9.0
Cisco Adaptive Security Appliance Software 9.1
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »