Page 2 of 12 results (0.000 seconds)

CVSS: 9.8EPSS: 2%CPEs: 2EXPL: 2

02 Sep 2005 — PHP remote file inclusion vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to execute arbitrary PHP code via the custom_welcome_page parameter. • http://marc.info/?l=bugtraq&m=112542447219235&w=2 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

30 Aug 2005 — phpldapadmin before 0.9.6c allows remote attackers to gain anonymous access to the LDAP server, even when disable_anon_bind is set, via an HTTP request to login.php with the anonymous_bind parameter set. • http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=322423 •