CVE-2007-1840
published 2007-04-03CVE-2007-1840: lib/modules.inc in LDAP Account Manager (LAM) before 1.3.0 does not escape HTML special characters in LDAP data, which allows remote attackers to have an…
PriorityP415medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.32%
68.1th percentile
lib/modules.inc in LDAP Account Manager (LAM) before 1.3.0 does not escape HTML special characters in LDAP data, which allows remote attackers to have an unknown impact, probably cross-site scripting (XSS).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ldap-account-manager | < ldap-account-manager 1.1.1-2 (bookworm) | ldap-account-manager 1.1.1-2 (bookworm) |
| ldap_account_manager | ldap_account_manager | <= 1.0_rc2 | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3855-5967-qfv2: lib/modules
ghsa_unreviewed·2022-05-01
CVE-2007-1840 [MEDIUM] GHSA-3855-5967-qfv2: lib/modules
lib/modules.inc in LDAP Account Manager (LAM) before 1.3.0 does not escape HTML special characters in LDAP data, which allows remote attackers to have an unknown impact, probably cross-site scripting (XSS).
OSV
CVE-2007-1840: lib/modules
osv·2007-04-03·CVSS 4.3
CVE-2007-1840 [MEDIUM] CVE-2007-1840: lib/modules
lib/modules.inc in LDAP Account Manager (LAM) before 1.3.0 does not escape HTML special characters in LDAP data, which allows remote attackers to have an unknown impact, probably cross-site scripting (XSS).
Debian
CVE-2007-1840: ldap-account-manager - lib/modules.inc in LDAP Account Manager (LAM) before 1.3.0 does not escape HTML ...
vendor_debian·2007·CVSS 4.3
CVE-2007-1840 [MEDIUM] CVE-2007-1840: ldap-account-manager - lib/modules.inc in LDAP Account Manager (LAM) before 1.3.0 does not escape HTML ...
lib/modules.inc in LDAP Account Manager (LAM) before 1.3.0 does not escape HTML special characters in LDAP data, which allows remote attackers to have an unknown impact, probably cross-site scripting (XSS).
Scope: local
bookworm: resolved (fixed in 1.1.1-2)
bullseye: resolved (fixed in 1.1.1-2)
forky: resolved (fixed in 1.1.1-2)
sid: resolved (fixed in 1.1.1-2)
trixie: resolved (fixed in 1.1.1-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lam.cvs.sourceforge.net/lam/lam/lib/modules.inc?r1=1.173&r2=1.174http://lam.sourceforge.net/changelog/index.htmhttp://secunia.com/advisories/24687http://secunia.com/advisories/25157http://www.securityfocus.com/bid/23190http://www.us.debian.org/security/2007/dsa-1287http://www.vupen.com/english/advisories/2007/1149https://exchange.xforce.ibmcloud.com/vulnerabilities/33307http://lam.cvs.sourceforge.net/lam/lam/lib/modules.inc?r1=1.173&r2=1.174http://lam.sourceforge.net/changelog/index.htmhttp://secunia.com/advisories/24687http://secunia.com/advisories/25157http://www.securityfocus.com/bid/23190http://www.us.debian.org/security/2007/dsa-1287http://www.vupen.com/english/advisories/2007/1149https://exchange.xforce.ibmcloud.com/vulnerabilities/33307
2007-04-03
Published