Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

phpLDAPadmin < 1.2 Local File Inclusion

High

Synopsis

The remote web server is hosting an application that is vulnerable to a local file inclusion attack.

Description

The remote web server is hosting phpLDAPadmin, a web-based LDAP client. The installed version of phpLDAPadmin is earlier than 1.2.0. Such versions are potentially affected by a local file inclusion vulnerability because the application fails to properly sanitize user-supplied input to the 'cmd' parameter of the 'cmd.php' script. An unauthenticated user could exploit this flaw to view arbitrary files or possibly execute arbitrary PHP code on the remote host subject to the privileges of the web server user id.

Solution

Upgrade to phpLDAPadmin 1.2.0 or later.