Description
The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby parameter (aka sortby variable) in a query_engine action to cmd.php, as exploited in the wild in October 2011.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2333-1 | phpldapadmin security update |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T23:53:32.825Z
Reserved: 2011-10-18T00:00:00.000Z
Link: CVE-2011-4075
No data.
Status : Modified
Published: 2011-11-02T17:55:01.387
Modified: 2026-04-29T01:13:23.040
Link: CVE-2011-4075
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA