vendor:
phpldapadmin
by:
ipsecs
7.5
CVSS
HIGH
Local File Inclusion
98
CWE
Product Name: phpldapadmin
Affected Version From: phpldapadmin 1.1.0.5
Affected Version To: phpldapadmin 1.1.0.5
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu 8.10, Debian 5.0
2009
PHPLDAPADMIN LOCAL FILE INCLUSION
Phpldapadmin is web based LDAP client which provides easy, anywhere-accessible, multi-language administration for LDAP server. Vulnerable code is found in cmd.php which doesn't sanitize URI parameter provided by user input. Attacker may view any arbitrary files trough 'cmd' parameter in URI request. Exploit example: http://server/phpldapadmin/cmd.php?cmd=../../../../etc/passwd%00 http://server/phpldapadmin/cmd.php?cmd=../../../../issue%00
Mitigation:
Sanitize $file before being included.