Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
phpldapadmin project phpldapadmin 1.2.2 vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2018-12689
phpLDAPadmin 1.2.2 allows LDAP injection via a crafted server_id parameter in a cmd.php?cmd=login_form request, or a crafted username and password in the login panel.
Phpldapadmin Project Phpldapadmin 1.2.2
NA
CVE-2011-4074
Cross-site scripting (XSS) vulnerability in cmd.php in phpLDAPadmin 1.2.x prior to 1.2.2 allows remote malicious users to inject arbitrary web script or HTML via an _debug command.
Phpldapadmin Project Phpldapadmin 1.2.0
Phpldapadmin Project Phpldapadmin 1.2.0.1
Phpldapadmin Project Phpldapadmin 1.2.0.2
Phpldapadmin Project Phpldapadmin 1.2.0.3
Phpldapadmin Project Phpldapadmin 1.2.0.4
Phpldapadmin Project Phpldapadmin 1.2.0.5
Phpldapadmin Project Phpldapadmin 1.2.1
Phpldapadmin Project Phpldapadmin 1.2.1.1
1 EDB exploit
NA
CVE-2011-4075
The masort function in lib/functions.php in phpLDAPadmin 1.2.x prior to 1.2.2 allows remote malicious users to execute arbitrary PHP code via the orderby parameter (aka sortby variable) in a query_engine action to cmd.php, as exploited in the wild in October 2011.
Phpldapadmin Project Phpldapadmin 1.2.0
Phpldapadmin Project Phpldapadmin 1.2.0.1
Phpldapadmin Project Phpldapadmin 1.2.0.2
Phpldapadmin Project Phpldapadmin 1.2.0.3
Phpldapadmin Project Phpldapadmin 1.2.0.4
Phpldapadmin Project Phpldapadmin 1.2.0.5
Phpldapadmin Project Phpldapadmin 1.2.1
Phpldapadmin Project Phpldapadmin 1.2.1.1
2 EDB exploits
NA
CVE-2012-0834
Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the base parameter in a query_engine action to cmd.php.
Phpldapadmin Project Phpldapadmin
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-26925
CVE-2023-41826
LFI
CVE-2022-22364
CVE-2024-2887
command injection
remote code execution
CVE-2024-34446
CVE-2022-48699
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started