Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
phpldapadmin vulnerabilities and exploits
(subscribe to this query)
5.4
CVSSv3
CVE-2020-35132
An XSS issue has been discovered in phpLDAPadmin prior to 1.2.6.2 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.
Phpldapadmin Project Phpldapadmin
Fedoraproject Fedora 32
Fedoraproject Fedora 33
7.5
CVSSv3
CVE-2011-4082
A local file inclusion flaw was found in the way the phpLDAPadmin prior to 0.9.8 processed certain values of the "Accept-Language" HTTP header. A remote attacker could use this flaw to cause a denial of service via specially-crafted request.
Phpldapadmin Project Phpldapadmin
Debian Debian Linux 8.0
Debian Debian Linux 9.0
Debian Debian Linux 10.0
9.8
CVSSv3
CVE-2018-12689
phpLDAPadmin 1.2.2 allows LDAP injection via a crafted server_id parameter in a cmd.php?cmd=login_form request, or a crafted username and password in the login panel.
Phpldapadmin Project Phpldapadmin 1.2.2
6.1
CVSSv3
CVE-2017-11107
phpLDAPadmin up to and including 1.2.3 has XSS in htdocs/entry_chooser.php via the form, element, rdn, or container parameter.
Phpldapadmin Project Phpldapadmin
Debian Debian Linux 8.0
NA
CVE-2012-0834
Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the base parameter in a query_engine action to cmd.php.
Phpldapadmin Project Phpldapadmin
1 EDB exploit
NA
CVE-2011-4074
Cross-site scripting (XSS) vulnerability in cmd.php in phpLDAPadmin 1.2.x prior to 1.2.2 allows remote malicious users to inject arbitrary web script or HTML via an _debug command.
Phpldapadmin Project Phpldapadmin 1.2.0
Phpldapadmin Project Phpldapadmin 1.2.0.1
Phpldapadmin Project Phpldapadmin 1.2.0.2
Phpldapadmin Project Phpldapadmin 1.2.0.3
Phpldapadmin Project Phpldapadmin 1.2.0.4
Phpldapadmin Project Phpldapadmin 1.2.0.5
Phpldapadmin Project Phpldapadmin 1.2.1
Phpldapadmin Project Phpldapadmin 1.2.1.1
1 EDB exploit
NA
CVE-2011-4075
The masort function in lib/functions.php in phpLDAPadmin 1.2.x prior to 1.2.2 allows remote malicious users to execute arbitrary PHP code via the orderby parameter (aka sortby variable) in a query_engine action to cmd.php, as exploited in the wild in October 2011.
Phpldapadmin Project Phpldapadmin 1.2.0
Phpldapadmin Project Phpldapadmin 1.2.0.1
Phpldapadmin Project Phpldapadmin 1.2.0.2
Phpldapadmin Project Phpldapadmin 1.2.0.3
Phpldapadmin Project Phpldapadmin 1.2.0.4
Phpldapadmin Project Phpldapadmin 1.2.0.5
Phpldapadmin Project Phpldapadmin 1.2.1
Phpldapadmin Project Phpldapadmin 1.2.1.1
2 EDB exploits
NA
CVE-2009-4427
Directory traversal vulnerability in cmd.php in phpLDAPadmin 1.1.0.5 allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the cmd parameter.
Phpldapadmin Project Phpldapadmin 1.1.0.5
1 EDB exploit
NA
CVE-2006-2016
Multiple cross-site scripting (XSS) vulnerabilities in phpLDAPadmin 0.9.8 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) dn parameter in (a) compare_form.php, (b) copy_form.php, (c) rename_form.php, (d) template_engine.php, a...
Phpldapadmin Project Phpldapadmin
Debian Debian Linux 3.0
Debian Debian Linux 3.1
5 EDB exploits
NA
CVE-2005-2793
PHP remote file inclusion vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote malicious users to execute arbitrary PHP code via the custom_welcome_page parameter.
Phpldapadmin Project Phpldapadmin 0.9.6
Phpldapadmin Project Phpldapadmin 0.9.7
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »