CVE-2013-4453
NONE EPSS 68.2%
Published Nov 5, 201312y ago · Modified Jun 16, 20262w ago
Published Nov 5, 2013 12y ago
Last Modified Jun 16, 2026 2w ago
Description
Cross-site scripting (XSS) vulnerability in templates/login.php in LDAP Account Manager (LAM) 4.3 and 4.2.1 allows remote attackers to inject arbitrary web script or HTML via the language parameter.
Threat Intelligence
EPSS Exploit Probability
68.2% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Weaknesses 1
CWE-79 Cross-site Scripting Injection
Affected Products 2
| Vendor | Product | Version | Range |
|---|---|---|---|
| ldap-account-manager | ldap_account_manager | 4.2.1 | any |
| ldap-account-manager | ldap_account_manager | 4.3 | any |
References 7
- bugs.debian.org http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=726976
- osvdb.org http://osvdb.org/98828
- seclists.org http://seclists.org/oss-sec/2013/q4/149
- secunia.com http://secunia.com/advisories/55413
- sourceforge.net http://sourceforge.net/p/lam/bugs/156
- rusty-ice.de http://www.rusty-ice.de/advisory/advisory_2013001.txt
- exchange.xforce.ibmcloud.com https://exchange.xforce.ibmcloud.com/vulnerabilities/88203
Remediation
- seclists.org http://seclists.org/oss-sec/2013/q4/149
- sourceforge.net http://sourceforge.net/p/lam/bugs/156
- rusty-ice.de http://www.rusty-ice.de/advisory/advisory_2013001.txt