Phamm (aka PHP LDAP Virtual Hosting Manager) 0.6.8 allows XSS via the login page (the /public/main.php action parameter).
{
"binaries": [
{
"binary_version": "0.6.2-1.2ubuntu1",
"binary_name": "phamm"
},
{
"binary_version": "0.6.2-1.2ubuntu1",
"binary_name": "phamm-ldap"
},
{
"binary_version": "0.6.2-1.2ubuntu1",
"binary_name": "phamm-ldap-amavis"
},
{
"binary_version": "0.6.2-1.2ubuntu1",
"binary_name": "phamm-ldap-vacation"
}
]
}
{
"binaries": [
{
"binary_version": "0.6.5-1ubuntu1",
"binary_name": "phamm"
},
{
"binary_version": "0.6.5-1ubuntu1",
"binary_name": "phamm-ldap"
},
{
"binary_version": "0.6.5-1ubuntu1",
"binary_name": "phamm-ldap-amavis"
},
{
"binary_version": "0.6.5-1ubuntu1",
"binary_name": "phamm-ldap-vacation"
}
]
}
{
"binaries": [
{
"binary_version": "0.6.5-1ubuntu1",
"binary_name": "phamm"
},
{
"binary_version": "0.6.5-1ubuntu1",
"binary_name": "phamm-ldap"
},
{
"binary_version": "0.6.5-1ubuntu1",
"binary_name": "phamm-ldap-amavis"
},
{
"binary_version": "0.6.5-1ubuntu1",
"binary_name": "phamm-ldap-vacation"
}
]
}
{
"binaries": [
{
"binary_version": "0.6.8-1ubuntu2",
"binary_name": "phamm"
},
{
"binary_version": "0.6.8-1ubuntu2",
"binary_name": "phamm-ldap"
},
{
"binary_version": "0.6.8-1ubuntu2",
"binary_name": "phamm-ldap-amavis"
},
{
"binary_version": "0.6.8-1ubuntu2",
"binary_name": "phamm-ldap-vacation"
}
]
}