Releases3
Frequency1 year 2 months
Last Release
Stars18
PHP LDAP Virtual Hosting Manager

CVE History

CVEPublishedCVSS v3CVSS v2
4.3 MEDIUM

Phamm (aka PHP LDAP Virtual Hosting Manager) 0.6.8 allows XSS via the login page (the /public/main.php action parameter).

4.3 MEDIUM

XSS exists in the login_form function in views/helpers.php in Phamm before 0.6.7, exploitable via the PATH_INFO to main.php.