VYPR

Phamm

by Phamm

Source repositories

CVEs (2)

  • CVE-2018-20806MedMar 17, 2019
    risk 0.40cvss 6.1epss 0.01

    Phamm (aka PHP LDAP Virtual Hosting Manager) 0.6.8 allows XSS via the login page (the /public/main.php action parameter).

  • CVE-2017-0378MedJul 20, 2017
    risk 0.40cvss 6.1epss 0.01

    XSS exists in the login_form function in views/helpers.php in Phamm before 0.6.7, exploitable via the PATH_INFO to main.php.