CVE-2005-2792 – phpLDAPadmin 0.9.6/0.9.7 - 'welcome.php' Arbitrary File Inclusion
https://notcve.org/view.php?id=CVE-2005-2792
Directory traversal vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the custom_welcome_page parameter. • https://www.exploit-db.com/exploits/26211 http://marc.info/?l=bugtraq&m=112542447219235&w=2 http://secunia.com/advisories/16617 http://www.rgod.altervista.org/phpldap.html http://www.securityfocus.com/bid/14695 https://exchange.xforce.ibmcloud.com/vulnerabilities/22103 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2005-2654
https://notcve.org/view.php?id=CVE-2005-2654
phpldapadmin before 0.9.6c allows remote attackers to gain anonymous access to the LDAP server, even when disable_anon_bind is set, via an HTTP request to login.php with the anonymous_bind parameter set. • http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=322423 http://www.debian.org/security/2005/dsa-790 http://www.gentoo.org/security/en/glsa/glsa-200509-04.xml •