Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.56712
Kategorie:FreeBSD Local Security Checks
Titel:FreeBSD Ports: phpldapadmin098
Zusammenfassung:The remote host is missing an update to the system; as announced in the referenced advisory.
Beschreibung:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following package is affected: phpldapadmin098

CVE-2006-2016
Multiple cross-site scripting (XSS) vulnerabilities in phpLDAPadmin
0.9.8 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) dn parameter in (a) compare_form.php, (b)
copy_form.php, (c) rename_form.php, (d) template_engine.php, and (e)
delete_form.php, (2) scope parameter in (f) search.php, and (3)
Container DN, (4) Machine Name, and (5) UID Number fields in (g)
template_engine.php.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
2.6

CVSS Vector:
AV:N/AC:H/Au:N/C:N/I:P/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2006-2016
BugTraq ID: 17643
http://www.securityfocus.com/bid/17643
Debian Security Information: DSA-1057 (Google Search)
http://www.debian.org/security/2006/dsa-1057
http://pridels0.blogspot.com/2006/04/phpldapadmin-multiple-vuln.html
http://www.osvdb.org/24788
http://www.osvdb.org/24789
http://www.osvdb.org/24790
http://www.osvdb.org/24792
http://www.osvdb.org/24793
http://www.osvdb.org/24794
http://secunia.com/advisories/19747
http://secunia.com/advisories/20124
http://www.vupen.com/english/advisories/2006/1450
XForce ISS Database: phpldapadmin-scope-dn-xss(25958)
https://exchange.xforce.ibmcloud.com/vulnerabilities/25958
XForce ISS Database: phpldapadmin-templateengine-xss(25959)
https://exchange.xforce.ibmcloud.com/vulnerabilities/25959
CopyrightCopyright (C) 2008 E-Soft Inc.

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.