CVE DATABASE / CVE-2006-7191
CVE-2006-7191
CVSS 7.2 · HIGH
Summary
Untrusted search path vulnerability in lamdaemon.pl in LDAP Account Manager (LAM) before 1.0.0 allows local users to gain privileges via a modified PATH that points to a malicious rm program.
CVSS 2.0 breakdown
| Base score | 7.2 (HIGH) |
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
| Attack vector | LOCAL |
| Attack complexity | LOW |
| Confidentiality | COMPLETE |
| Integrity | COMPLETE |
| Availability | COMPLETE |
Affected products
Ldap_account_manager ldap account manager
Check this CVE live
Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.
References
- http://lam.cvs.sourceforge.net/lam/lam/lib/lamdaemon.pl
- http://lam.cvs.sourceforge.net/lam/lam/lib/lamdaemon.pl?r1=1.32&r2=1.33
- http://lam.sourceforge.net/changelog/index.htm
- http://secunia.com/advisories/25157
- http://www.securityfocus.com/bid/23857
- http://www.us.debian.org/security/2007/dsa-1287
Data: NIST NVD. NVD last modified 2026-04-23. Always verify against the vendor advisory before acting.