LWN.net Logo

phpldapadmin: cross-site scripting

Package(s):phpldapadmin CVE #(s):CVE-2012-0834
Created:February 14, 2012 Updated:February 15, 2012
Description: From the CVE entry:

Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the base parameter in a query_engine action to cmd.php.

Alerts:
Fedora FEDORA-2012-1253 2012-02-14
Fedora FEDORA-2012-1267 2012-02-14
Mandriva MDVSA-2012:020 2012-02-15

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds