Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2018-8763
Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 has XSS via the dn parameter to the templates/3rdParty/pla/htdocs/cmd.php URI or the template parameter to the templates/3rdParty/pla/htdocs/cmd.php?cmd=rename_form URI.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.004
EPSS Ranking
62.5%
CVSS Severity
CVSS v3 Score
6.1
CVSS v2 Score
4.3
References
http://packetstormsecurity.com/files/146858/LDAP-Account-Manager-6.2-Cross-Site-Scripting.html
http://seclists.org/fulldisclosure/2018/Mar/45
https://lists.debian.org/debian-lts-announce/2018/04/msg00007.html
https://www.debian.org/security/2018/dsa-4165
http://packetstormsecurity.com/files/146858/LDAP-Account-Manager-6.2-Cross-Site-Scripting.html
http://seclists.org/fulldisclosure/2018/Mar/45
https://lists.debian.org/debian-lts-announce/2018/04/msg00007.html
https://www.debian.org/security/2018/dsa-4165
Products affected by CVE-2018-8763
Ldap-Account-Manager
»
Ldap Account Manager
»
Version:
N/A
cpe:2.3:a:ldap-account-manager:ldap_account_manager:-
Ldap-Account-Manager
»
Ldap Account Manager
»
Version:
3.6
cpe:2.3:a:ldap-account-manager:ldap_account_manager:3.6
Ldap-Account-Manager
»
Ldap Account Manager
»
Version:
4.2.1
cpe:2.3:a:ldap-account-manager:ldap_account_manager:4.2.1
Ldap-Account-Manager
»
Ldap Account Manager
»
Version:
4.3
cpe:2.3:a:ldap-account-manager:ldap_account_manager:4.3
Debian
»
Debian Linux
»
Version:
7.0
cpe:2.3:o:debian:debian_linux:7.0
Debian
»
Debian Linux
»
Version:
8.0
cpe:2.3:o:debian:debian_linux:8.0
Debian
»
Debian Linux
»
Version:
9.0
cpe:2.3:o:debian:debian_linux:9.0
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved