PT-2012-2895 · Phpldapadmin · Phpldapadmin
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
phpLDAPadmin versions 1.2.2 and earlier
Description
The issue is related to a cross-site scripting (XSS) vulnerability. This vulnerability allows remote attackers to inject arbitrary web script or HTML via the
base parameter in a query engine action to cmd.php.Recommendations
For phpLDAPadmin versions 1.2.2 and earlier, consider disabling access to the
query engine action in cmd.php until a patch is available. Restrict input for the base parameter to prevent injection of malicious scripts.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Phpldapadmin