2.6
CVSSv2

CVE-2006-2016

Published: 25/04/2006 Updated: 16/11/2020
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 285
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in phpLDAPadmin 0.9.8 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) dn parameter in (a) compare_form.php, (b) copy_form.php, (c) rename_form.php, (d) template_engine.php, and (e) delete_form.php; (2) scope parameter in (f) search.php; and (3) Container DN, (4) Machine Name, and (5) UID Number fields in (g) template_engine.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

phpldapadmin project phpldapadmin

debian debian linux 3.0

debian debian linux 3.1

Vendor Advisories

Debian Bug report logs - #365313 CVE-2006-2016: multiple xss vulnerabilities in phpldapadmin Package: phpldapadmin; Maintainer for phpldapadmin is Fabio Tranchitella <kobold@debianorg>; Source for phpldapadmin is src:phpldapadmin (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschde> Date: Sat, 29 Apr 20 ...
Several cross-site scripting vulnerabilities have been discovered in phpLDAPadmin, a web based interface for administering LDAP servers, that allows remote attackers to inject arbitrary web script or HTML The old stable distribution (woody) does not contain phpldapadmin packages For the stable distribution (sarge) these problems have been fixed i ...

Exploits

source: wwwsecurityfocuscom/bid/17643/info PHPLDAPAdmin is prone to multiple input-validation vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input An attacker can exploit these issues to execute arbitrary HTML and script code in the browser of a victim user in the context of ...
source: wwwsecurityfocuscom/bid/17643/info PHPLDAPAdmin is prone to multiple input-validation vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input An attacker can exploit these issues to execute arbitrary HTML and script code in the browser of a victim user in the conte ...
source: wwwsecurityfocuscom/bid/17643/info PHPLDAPAdmin is prone to multiple input-validation vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input An attacker can exploit these issues to execute arbitrary HTML and script code in the browser of a victim user in the context ...
source: wwwsecurityfocuscom/bid/17643/info PHPLDAPAdmin is prone to multiple input-validation vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input An attacker can exploit these issues to execute arbitrary HTML and script code in the browser of a victim user in the context of th ...
source: wwwsecurityfocuscom/bid/17643/info PHPLDAPAdmin is prone to multiple input-validation vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input An attacker can exploit these issues to execute arbitrary HTML and script code in the browser of a victim user in the context of the ...