Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Debian: DSA-2333-1 Critical PHP Code Execution Risk in Phpldapadmin

debian
Calendar Grey October 30, 2011
Debian Logo
Recent vulnerabilities in phpldapadmin expose users to potential remote code execution threats. It is imperative for all users to update to the most recent version without delay.
Two vulnerabilities have been discovered in phpldapadmin, a web based interface for administering LDAP servers

Summary

Two vulnerabilities have been discovered in phpldapadmin, a web based
interface for administering LDAP servers. The Common Vulnerabilities and
Exposures project identifies the following problems:

CVE-2011-4074

Input appended to the URL in cmd.php (when "cmd" is set to "_debug") is
not properly sanitised before being returned to the user. This can be
exploited to execute arbitrary HTML and script code in a user's browser
session in context of an affected site.

CVE-2011-4075

Input passed to the "orderby" parameter in cmd.php (when "cmd" is set to
"query_engine", "query" is set to "none", and "search" is set to e.g.
"1") is not properly sanitised in lib/functions.php before being used in a
"create_function()" function call. This can be exploited to inject and
execute arbitrary PHP code.


For the oldstable distribution (lenny), these problems have been fixed in
version 1.1.0.5-6+lenny2.

For the stable distribution (squeeze), these problems have been fixed in
version 1.2.0.5-2+squeeze1.

F...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: phpldapadmin

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here