Vulnerabilities (CVE)

Filtered by vendor Phamm Subscribe
Filtered by product Phamm
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-20806 1 Phamm 1 Phamm 2023-12-10 4.3 MEDIUM 6.1 MEDIUM
Phamm (aka PHP LDAP Virtual Hosting Manager) 0.6.8 allows XSS via the login page (the /public/main.php action parameter).
CVE-2017-0378 1 Phamm 1 Phamm 2023-12-10 4.3 MEDIUM 6.1 MEDIUM
XSS exists in the login_form function in views/helpers.php in Phamm before 0.6.7, exploitable via the PATH_INFO to main.php.