Php · Phpldapadmin · CVE-2009-4427
**Name of the Vulnerable Software and Affected Versions**
phpLDAPadmin version 1.1.0.5
**Description**
The issue allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the `cmd` parameter of the cmd.php file.
**Recommendations**
For phpLDAPadmin version 1.1.0.5, consider restricting access to the cmd.php file to minimize the risk of exploitation. Avoid using the `cmd` parameter in the affected API endpoint until the issue is resolved.