Self Service Password Unspecified LDAP Injection Vulnerability
BID:56163
Info
Self Service Password Unspecified LDAP Injection Vulnerability
| Bugtraq ID: | 56163 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 22 2012 12:00AM |
| Updated: | Oct 22 2012 12:00AM |
| Credit: | Reported by the vendor |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Self Service Password Unspecified LDAP Injection Vulnerability
Self Service Password is prone to an unspecified vulnerability regarding an LDAP injection.
Exploiting this issue could allow an attacker to access or modify data, or exploit latent vulnerabilities in the underlying distributed directory information services.
Versions prior to Self Service Password 0.8 are vulnerable.
Self Service Password is prone to an unspecified vulnerability regarding an LDAP injection.
Exploiting this issue could allow an attacker to access or modify data, or exploit latent vulnerabilities in the underlying distributed directory information services.
Versions prior to Self Service Password 0.8 are vulnerable.
Exploit / POC
Self Service Password Unspecified LDAP Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Self Service Password Unspecified LDAP Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Self Service Password Unspecified LDAP Injection Vulnerability
References:
References: