VendorsphpLDAPadmin Projectphpldapadmin1.2.0.3
Vulnerabilities

phpLDAPadmin Project phpLDAPadmin 1.2.0.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2011-4075
The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby parameter (aka sortby variable) in a query_engine action to cmd.php, as exploited in the wild in October 2011.
Published 2011-11-02 · Modified
7.52 PoCEPSS 0.519
CVE-2011-4074
Cross-site scripting (XSS) vulnerability in cmd.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via an _debug command.
Published 2011-11-02 · Modified
4.31 PoCEPSS 0.054