Ldap Account Manager
ldap_account_manager
16 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (16)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ldap Account Manager 1Ldap Account Manager Mar 23, 2026 Mar 18, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, the PDF export component does not correctly validate uploaded file e...Show more |
1Ldap Account Manager 1Ldap Account Manager Mar 23, 2026 Mar 18, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, a local file inclusion was detected in the PDF export that allows us...Show more |
1Ldap Account Manager 1Ldap Account Manager Dec 23, 2025 Mar 18, 2024 N/A· v4 6.6 MEDIUM· v3 N/A· v2 LDAP Account Manager (LAM) is a webfrontend for managing entries stored in an LDAP directory. LAM's log configuration allows to specify arbitrary paths for log files. Prior to version 8.7, an attacker could exploit this...Show more |
2Debian Ldap Account Manager2Debian Linux Ldap Account ManagerNov 21, 2024 Jun 27, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the user name field at login could be used to enumerate LDAP data...Show more |
2Debian Ldap Account Manager2Debian Linux Ldap Account ManagerNov 21, 2024 Jun 27, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the tmp directory, which is accessible by /lam/tmp/, allows inter...Show more |
2Debian Ldap Account Manager2Debian Linux Ldap Account ManagerNov 21, 2024 Jun 27, 2022 N/A· v4 8.8 HIGH· v3 6.0 MEDIUM· v2 LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 incorrect regular expressions allow to upload PHP scripts to conf...Show more |
2Debian Ldap Account Manager2Debian Linux Ldap Account ManagerNov 21, 2024 Jun 27, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the session files include the LDAP user name and password in clea...Show more |
2Debian Ldap Account Manager2Debian Linux Ldap Account ManagerNov 21, 2024 Jun 27, 2022 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 There are cases where LAM instantiates objects from arbitrary cla...Show more |
2Debian Ldap Account Manager2Debian Linux Ldap Account ManagerNov 21, 2024 Apr 15, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 LDAP Account Manager (LAM) is an open source web frontend for managing entries stored in an LDAP directory. The profile editor tool has an edit profile functionality, the parameters on this page are not properly sanitize...Show more |
3Debian FedoraprojectLdap Account Manager3Debian Linux FedoraLdap Account ManagerNov 21, 2024 Dec 5, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, add_value_form, and dn parameters to cmd.php. |
3Debian FedoraprojectLdap Account Manager3Debian Linux FedoraLdap Account ManagerNov 21, 2024 Dec 5, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filter parameter to cmd.php in an export and exporter_id action. and the filteruid parameter to list.php. |
2Debian Ldap Account Manager2Debian Linux Ldap Account ManagerNov 21, 2024 Mar 27, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for remote attackers to defeat a CSRF protection mechanism by leveraging lo...Show more |
2Debian Ldap Account Manager2Debian Linux Ldap Account ManagerNov 21, 2024 Mar 27, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 has XSS via the dn parameter to the templates/3rdParty/pla/htdocs/cmd.php URI or the template parameter to the templates/3rdParty/pla/htdocs/cmd.php?cmd=r...Show more |
1Ldap Account Manager 1Ldap Account Manager Apr 29, 2026 Nov 5, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in templates/login.php in LDAP Account Manager (LAM) 4.3 and 4.2.1 allows remote attackers to inject arbitrary web script or HTML via the language parameter. |
1Ldap Account Manager 1Ldap Account Manager Apr 23, 2026 Apr 3, 2007 N/A· v4 N/A· v3 4.3 MEDIUM· v2 lib/modules.inc in LDAP Account Manager (LAM) before 1.3.0 does not escape HTML special characters in LDAP data, which allows remote attackers to have an unknown impact, probably cross-site scripting (XSS). |
1Ldap Account Manager 1Ldap Account Manager Apr 23, 2026 Apr 3, 2007 N/A· v4 N/A· v3 7.2 HIGH· v2 Untrusted search path vulnerability in lamdaemon.pl in LDAP Account Manager (LAM) before 1.0.0 allows local users to gain privileges via a modified PATH that points to a malicious rm program. |