XSS exists in the login_form function in views/helpers.php in Phamm before 0.6.7, exploitable via the PATH_INFO to main.php.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/99927 | vdb entry third party advisory |
http://www.openwall.com/lists/oss-security/2017/07/20/3 | third party advisory mailing list |
https://github.com/lota/phamm/issues/21 | issue tracking exploit third party advisory |
https://bugs.debian.org/868988 | third party advisory mailing list |
http://www.phamm.org/docs/CHANGELOG | vendor advisory |