mailing list archives
Re: CVE Request -- LDAP Account Manager Pro / PhpLDAPadmin -- Multiple XSS flaws
From: Roland Gruber <post () rolandgruber de>
Date: Mon, 05 Mar 2012 20:56:59 +0100
On 05.03.2012 11:36, Jan Lieskovsky wrote:
Wrt to PhpLDAPAdmin side -- I am not sure, what's the relation of the
code between LAM and
PLA (if PLA is using / embedding some code of LAM directly or if there
were also some
customizations on the side of PLA upon LAM code embedding / inclusion).
Fabio, Dmitry can clarify here, how much the PhpLDAPAdmin code is
different from LDAP
Account Manager code (if it's just overtaken LAM code or PhpLDAPAdmin
have also made
their own customizations to the code)?
LDAP Account Manager includes a reduced copy of the phpLDAPadmin code. I already checked if phpLDAPadmin contains a fix
and it seems to be vulnerable,
too. Therefore, I cloned the Debian bug.
The Debian bug report contains a patch for Debian Stable. Debian packages for Unstable are here: