Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ldap account manager vulnerabilities and exploits
(subscribe to this query)
383
VMScore
CVE-2018-8763
Roland Gruber Softwareentwicklung LDAP Account Manager prior to 6.3 has XSS via the dn parameter to the templates/3rdParty/pla/htdocs/cmd.php URI or the template parameter to the templates/3rdParty/pla/htdocs/cmd.php?cmd=rename_form URI.
Debian Debian Linux 9.0
Debian Debian Linux 8.0
Debian Debian Linux 7.0
Ldap-account-manager Ldap Account Manager
383
VMScore
CVE-2012-1114
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filter parameter to cmd.php in an export and exporter_id action. and the filteruid parameter to list.php.
Ldap-account-manager Ldap Account Manager 3.6
Debian Debian Linux 8.0
Debian Debian Linux 9.0
Fedoraproject Fedora 16
Fedoraproject Fedora 17
Fedoraproject Fedora 18
383
VMScore
CVE-2012-1115
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, add_value_form, and dn parameters to cmd.php.
Ldap-account-manager Ldap Account Manager 3.6
Debian Debian Linux 8.0
Debian Debian Linux 9.0
Fedoraproject Fedora 16
Fedoraproject Fedora 17
Fedoraproject Fedora 18
NA
CVE-2024-23333
LDAP Account Manager (LAM) is a webfrontend for managing entries stored in an LDAP directory. LAM's log configuration allows to specify arbitrary paths for log files. Prior to version 8.7, an attacker could exploit this by creating a PHP file and cause LAM to log some PHP co...
312
VMScore
CVE-2017-7568
NetApp OnCommand Unified Manager for 7-Mode (core package) versions before 5.2.3 may disclose sensitive LDAP account information to authenticated users when the LDAP authentication configuration is tested via the user interface.
Netapp Oncommand Unified Manager
890
VMScore
CVE-2015-0546
EMC Unified Infrastructure Manager/Provisioning (UIM/P) 4.1 allows remote malicious users to bypass LDAP authentication by providing a valid account name.
Emc Unified Infrastructure Manager\\/provisioning 4.1
668
VMScore
CVE-2017-4976
EMC ESRS Policy Manager before 6.8 contains an undocumented account (OpenDS admin) with a default password. A remote attacker with the knowledge of the default password may login to the system and gain administrator privileges to the local LDAP directory server.
Emc Esrs Policy Manager
1000
VMScore
CVE-2021-44228
Apache Log4j2 2.0-beta9 up to and including 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can contr...
Apache Log4j 2.0
Apache Log4j
Siemens Sppa-t3000 Ses3000 Firmware
Siemens Logo\\! Soft Comfort
Siemens Spectrum Power 4 4.70
Siemens Spectrum Power 4
Siemens Siveillance Control Pro
Siemens Energyip Prepay 3.7
Siemens Energyip Prepay 3.8
Siemens Siveillance Identity 1.6
Siemens Siveillance Identity 1.5
Siemens Siveillance Command
Siemens Sipass Integrated 2.85
Siemens Sipass Integrated 2.80
Siemens Head-end System Universal Device Integration System
Siemens Gma-manager
Siemens Energyip 8.5
Siemens Energyip 8.6
Siemens Energyip 8.7
Siemens Energyip 9.0
Siemens Energy Engage 3.1
Siemens E-car Operation Center
2 Metasploit modules
1180 Github repositories
28 Articles
632
VMScore
CVE-2013-5507
The IPsec implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1 prior to 9.1(1.7), when an IPsec VPN tunnel is enabled, allows remote malicious users to cause a denial of service (device reload) via a (1) ICMP or (2) ICMPv6 packet that is improperly handled durin...
Cisco Adaptive Security Appliance Software 9.1
890
VMScore
CVE-2013-5509
The SSL implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0 prior to 9.0(2.6) and 9.1 prior to 9.1(2) allows remote malicious users to bypass authentication, and obtain VPN access or administrative access, via a crafted X.509 client certificate, aka Bug ID CSCu...
Cisco Adaptive Security Appliance Software 9.0
Cisco Adaptive Security Appliance Software 9.1
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-40673
CVE-2024-36674
CVE-2024-27348
unspecified
CVE-2024-24919
CVE-2024-4870
malicious code
CVE-2024-2019
hard-coded
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »