XSS exists in the loginform function in views/helpers.php in Phamm before 0.6.7, exploitable via the PATHINFO to main.php.
{
"binaries": [
{
"binary_name": "phamm",
"binary_version": "0.6.2-1.2ubuntu1"
},
{
"binary_name": "phamm-ldap",
"binary_version": "0.6.2-1.2ubuntu1"
},
{
"binary_name": "phamm-ldap-amavis",
"binary_version": "0.6.2-1.2ubuntu1"
},
{
"binary_name": "phamm-ldap-vacation",
"binary_version": "0.6.2-1.2ubuntu1"
}
]
}
{
"binaries": [
{
"binary_name": "phamm",
"binary_version": "0.6.5-1ubuntu1"
},
{
"binary_name": "phamm-ldap",
"binary_version": "0.6.5-1ubuntu1"
},
{
"binary_name": "phamm-ldap-amavis",
"binary_version": "0.6.5-1ubuntu1"
},
{
"binary_name": "phamm-ldap-vacation",
"binary_version": "0.6.5-1ubuntu1"
}
]
}
{
"binaries": [
{
"binary_name": "phamm",
"binary_version": "0.6.5-1ubuntu1"
},
{
"binary_name": "phamm-ldap",
"binary_version": "0.6.5-1ubuntu1"
},
{
"binary_name": "phamm-ldap-amavis",
"binary_version": "0.6.5-1ubuntu1"
},
{
"binary_name": "phamm-ldap-vacation",
"binary_version": "0.6.5-1ubuntu1"
}
]
}
{
"binaries": [
{
"binary_name": "phamm",
"binary_version": "0.6.8-1ubuntu2"
},
{
"binary_name": "phamm-ldap",
"binary_version": "0.6.8-1ubuntu2"
},
{
"binary_name": "phamm-ldap-amavis",
"binary_version": "0.6.8-1ubuntu2"
},
{
"binary_name": "phamm-ldap-vacation",
"binary_version": "0.6.8-1ubuntu2"
}
]
}