Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.56712
Kategorie:FreeBSD Local Security Checks
Titel:FreeBSD Ports: phpldapadmin098
Zusammenfassung:NOSUMMARY
Beschreibung:Description:
The remote host is missing an update to the system
as announced in the referenced advisory.

The following package is affected: phpldapadmin098

CVE-2006-2016
Multiple cross-site scripting (XSS) vulnerabilities in phpLDAPadmin
0.9.8 and earlier allow remote attackers to inject arbitrary web
script or HTML via the (1) dn parameter in (a) compare_form.php, (b)
copy_form.php, (c) rename_form.php, (d) template_engine.php, and (e)
delete_form.php
(2) scope parameter in (f) search.php
and (3)
Container DN, (4) Machine Name, and (5) UID Number fields in (g)
template_engine.php.

Solution:
Update your system with the appropriate patches or
software upgrades.

http://pridels.blogspot.com/2006/04/phpldapadmin-multiple-vuln.html
http://www.frsirt.com/english/advisories/2006/1450
http://secunia.com/advisories/19747/
http://www.vuxml.org/freebsd/6d78202e-e2f9-11da-8674-00123ffe8333.html

CVSS Score:
2.6

CVSS Vector:
AV:N/AC:H/Au:N/C:N/I:P/A:N

Querverweis: BugTraq ID: 17643
Common Vulnerability Exposure (CVE) ID: CVE-2006-2016
http://www.securityfocus.com/bid/17643
Debian Security Information: DSA-1057 (Google Search)
http://www.debian.org/security/2006/dsa-1057
http://pridels0.blogspot.com/2006/04/phpldapadmin-multiple-vuln.html
http://www.osvdb.org/24788
http://www.osvdb.org/24789
http://www.osvdb.org/24790
http://www.osvdb.org/24792
http://www.osvdb.org/24793
http://www.osvdb.org/24794
http://secunia.com/advisories/19747
http://secunia.com/advisories/20124
http://www.vupen.com/english/advisories/2006/1450
XForce ISS Database: phpldapadmin-scope-dn-xss(25958)
https://exchange.xforce.ibmcloud.com/vulnerabilities/25958
XForce ISS Database: phpldapadmin-templateengine-xss(25959)
https://exchange.xforce.ibmcloud.com/vulnerabilities/25959
CopyrightCopyright (c) 2006 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.