Vulnerabilities > Phpldapadmin Project

DATE CVE VULNERABILITY TITLE RISK
2020-12-11 CVE-2020-35132 Cross-site Scripting vulnerability in multiple products
An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.
network
low complexity
phpldapadmin-project fedoraproject CWE-79
5.4
2019-11-26 CVE-2011-4082 Resource Exhaustion vulnerability in multiple products
A local file inclusion flaw was found in the way the phpLDAPadmin before 0.9.8 processed certain values of the "Accept-Language" HTTP header.
network
low complexity
phpldapadmin-project debian CWE-400
7.5
2018-06-22 CVE-2018-12689 Unspecified vulnerability in PHPldapadmin Project PHPldapadmin 1.2.2
phpLDAPadmin 1.2.2 allows LDAP injection via a crafted server_id parameter in a cmd.php?cmd=login_form request, or a crafted username and password in the login panel.
network
low complexity
phpldapadmin-project
critical
9.8
2017-07-08 CVE-2017-11107 Cross-site Scripting vulnerability in multiple products
phpLDAPadmin through 1.2.3 has XSS in htdocs/entry_chooser.php via the form, element, rdn, or container parameter.
network
low complexity
phpldapadmin-project debian CWE-79
6.1