CVE-2005-2793
https://notcve.org/view.php?id=CVE-2005-2793
PHP remote file inclusion vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to execute arbitrary PHP code via the custom_welcome_page parameter. • http://marc.info/?l=bugtraq&m=112542447219235&w=2 http://secunia.com/advisories/16617 http://www.rgod.altervista.org/phpldap.html http://www.securityfocus.com/bid/14695 https://exchange.xforce.ibmcloud.com/vulnerabilities/22103 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2005-2792 – phpLDAPadmin 0.9.6/0.9.7 - 'welcome.php' Arbitrary File Inclusion
https://notcve.org/view.php?id=CVE-2005-2792
Directory traversal vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the custom_welcome_page parameter. • https://www.exploit-db.com/exploits/26211 http://marc.info/?l=bugtraq&m=112542447219235&w=2 http://secunia.com/advisories/16617 http://www.rgod.altervista.org/phpldap.html http://www.securityfocus.com/bid/14695 https://exchange.xforce.ibmcloud.com/vulnerabilities/22103 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •