LWN.net Logo

phpldapadmin: multiple vulnerabilities

Package(s):phpldapadmin CVE #(s):CVE-2011-4075 CVE-2011-4074
Created:October 31, 2011 Updated:November 25, 2011
Description: From the Debian advisory:

CVE-2011-4074: Input appended to the URL in cmd.php (when "cmd" is set to "_debug") is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

CVE-2011-4075: Input passed to the "orderby" parameter in cmd.php (when "cmd" is set to "query_engine", "query" is set to "none", and "search" is set to e.g. "1") is not properly sanitised in lib/functions.php before being used in a "create_function()" function call. This can be exploited to inject and execute arbitrary PHP code.

Alerts:
Fedora FEDORA-2011-14986 2011-10-27
Fedora FEDORA-2011-14993 2011-10-27
Fedora FEDORA-2011-14924 2011-10-25
Mandriva MDVSA-2011:163 2011-11-02
Debian DSA-2333-1 2011-10-31

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds