Candidate: CVE-2012-1114 PublicDate: 2019-12-05 21:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1114 Description: A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filter parameter to cmd.php in an export and exporter_id action. and the filteruid parameter to list.php. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=662050 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=661904 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N [6.1 MEDIUM] Patches_phpldapadmin: upstream_phpldapadmin: released (1.2.2-3) hardy_phpldapadmin: ignored (reached end-of-life) lucid_phpldapadmin: ignored (reached end-of-life) maverick_phpldapadmin: ignored (reached end-of-life) natty_phpldapadmin: ignored (reached end-of-life) oneiric_phpldapadmin: ignored (reached end-of-life) precise_phpldapadmin: not-affected (1.2.2-4ubuntu1) quantal_phpldapadmin: not-affected (1.2.2-4ubuntu1) raring_phpldapadmin: not-affected (1.2.2-4ubuntu1) saucy_phpldapadmin: not-affected (1.2.2-4ubuntu1) devel_phpldapadmin: not-affected (1.2.2-4ubuntu1) Patches_ldap-account-manager: upstream_ldap-account-manager: released (3.6-2) hardy_ldap-account-manager: ignored (reached end-of-life) lucid_ldap-account-manager: ignored (reached end-of-life) maverick_ldap-account-manager: ignored (reached end-of-life) natty_ldap-account-manager: ignored (reached end-of-life) oneiric_ldap-account-manager: ignored (reached end-of-life) precise_ldap-account-manager: not-affected (3.6-2) quantal_ldap-account-manager: not-affected (3.7-1) raring_ldap-account-manager: not-affected (3.7-1) saucy_ldap-account-manager: not-affected (3.7-1) devel_ldap-account-manager: not-affected (3.7-1)