phpldapadmin prior to 0.9.6c allows remote malicious users to gain anonymous access to the LDAP server, even when disable_anon_bind is set, via an HTTP request to login.php with the anonymous_bind parameter set.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
phpldapadmin project phpldapadmin |