Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the base parameter in a query_engine action to cmd.php.
http://www.mandriva.com/security/advisories?name=MDVSA-2012:020
http://secunia.com/advisories/47852
http://openwall.com/lists/oss-security/2012/02/03/3
http://openwall.com/lists/oss-security/2012/02/02/9
http://phpldapadmin.git.sourceforge.net/git/gitweb.cgi?p=phpldapadmin/phpldapadmin%3Ba=commit%3Bh=7dc8d57d6952fe681cb9e8818df7f103220457bd
Source: Mitre, NVD
Published: 2012-02-11
Updated: 2025-04-11
Base Score: 4.3
Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N
Severity: Medium
Base Score: 6.1
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS: 0.10038