phpLDAPadmin Cross Site Scripting and PHP Code Injection Vulnerabilities
BID:50331
Info
phpLDAPadmin Cross Site Scripting and PHP Code Injection Vulnerabilities
| Bugtraq ID: | 50331 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-4075 CVE-2011-4074 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 23 2011 12:00AM |
| Updated: | May 07 2015 05:05PM |
| Credit: | EgiX and phpLDAPadmin |
| Vulnerable: |
phpldapadmin phpldapadmin 1.2 phpldapadmin phpldapadmin 1.2.1.1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
phpLDAPadmin Cross Site Scripting and PHP Code Injection Vulnerabilities
phpLDAPadmin is prone to a cross-site scripting vulnerability and a PHP code-injection vulnerability.
An attacker can exploit these issues to execute arbitrary script code in the context of the affected site or inject and execute arbitrary PHP code in the context of the affected application. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
phpLDAPadmin versions 1.2.0 through 1.2.1.1 are vulnerable.
phpLDAPadmin is prone to a cross-site scripting vulnerability and a PHP code-injection vulnerability.
An attacker can exploit these issues to execute arbitrary script code in the context of the affected site or inject and execute arbitrary PHP code in the context of the affected application. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
phpLDAPadmin versions 1.2.0 through 1.2.1.1 are vulnerable.
Exploit / POC
phpLDAPadmin Cross Site Scripting and PHP Code Injection Vulnerabilities
Attackers can exploit these issues through a browser.
The following exploits are available:
Attackers can exploit these issues through a browser.
The following exploits are available:
Solution / Fix
phpLDAPadmin Cross Site Scripting and PHP Code Injection Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5
MandrakeSoft Enterprise Server 5 x86_64
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5
-
Mandriva phpldapadmin-1.2.2-0.1mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva phpldapadmin-1.2.2-0.1mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/
References
phpLDAPadmin Cross Site Scripting and PHP Code Injection Vulnerabilities
References:
References:
- PHP Code Injection Vulnerability - ID: 3417184 (phpLDAPadmin)
- phpldapadmin Homepage (phpldapadmin)
- Remove XSS vulnerabilty in debug code (phpLDAPadmin)