oss-sec mailing list archives
Re: CVE Request -- LDAP Account Manager Pro / PhpLDAPadmin -- Multiple XSS flaws
From: Roland Gruber <post () rolandgruber de>
Date: Mon, 05 Mar 2012 20:56:59 +0100
Hi all, On 05.03.2012 11:36, Jan Lieskovsky wrote:
Wrt to PhpLDAPAdmin side -- I am not sure, what's the relation of the code between LAM and PLA (if PLA is using / embedding some code of LAM directly or if there were also some customizations on the side of PLA upon LAM code embedding / inclusion). Hopefully Roland, Fabio, Dmitry can clarify here, how much the PhpLDAPAdmin code is different from LDAP Account Manager code (if it's just overtaken LAM code or PhpLDAPAdmin have also made their own customizations to the code)?
LDAP Account Manager includes a reduced copy of the phpLDAPadmin code. I already checked if phpLDAPadmin contains a fix and it seems to be vulnerable, too. Therefore, I cloned the Debian bug. The Debian bug report contains a patch for Debian Stable. Debian packages for Unstable are here: http://www.ldap-account-manager.org/static/debian-packages/ -- Best regards Roland
Current thread:
- CVE Request -- LDAP Account Manager Pro / PhpLDAPadmin -- Multiple XSS flaws Jan Lieskovsky (Mar 05)
- Re: CVE Request -- LDAP Account Manager Pro / PhpLDAPadmin -- Multiple XSS flaws Kurt Seifried (Mar 05)
- Re: CVE Request -- LDAP Account Manager Pro / PhpLDAPadmin -- Multiple XSS flaws Jan Lieskovsky (Mar 12)
- Re: CVE Request -- LDAP Account Manager Pro / PhpLDAPadmin -- Multiple XSS flaws Roland Gruber (Mar 12)
- Re: CVE Request -- LDAP Account Manager Pro / PhpLDAPadmin -- Multiple XSS flaws Jan Lieskovsky (Mar 12)
- Re: CVE Request -- LDAP Account Manager Pro / PhpLDAPadmin -- Multiple XSS flaws Roland Gruber (Mar 05)
- Re: CVE Request -- LDAP Account Manager Pro / PhpLDAPadmin -- Multiple XSS flaws Dmitry Butskoy (Mar 06)
- Re: CVE Request -- LDAP Account Manager Pro / PhpLDAPadmin -- Multiple XSS flaws Kurt Seifried (Mar 05)