HIGH
phpldapadmin: local file inclusion vulnerability
Published Dec 28, 2009
7.5
HIGHCVSS 2.0
EPSS 10.00%
Description
Directory traversal vulnerability in cmd.php in phpLDAPadmin 1.1.0.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cmd parameter.
Affected products
No data.
- 1.1.0.5
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (9)
- http://secunia.com/advisories/37848 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://www.exploit-db.com/exploits/10410 exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:023 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.osvdb.org/61139 vdb-entryx_refsource_OSVDBBroken LinkExploit
- http://www.securityfocus.com/bid/37327 vdb-entryx_refsource_BIDExploitThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2009-4427 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=549559 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2009-4427
- https://www.cve.org/CVERecord?id=CVE-2009-4427
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/37848 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://www.exploit-db.com/exploits/10410 | exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry | |
| http://www.mandriva.com/security/advisories?name=MDVSA-2010:023 | vendor-advisoryx_refsource_MANDRIVAThird Party Advisory | |
| http://www.osvdb.org/61139 | vdb-entryx_refsource_OSVDBBroken LinkExploit | |
| http://www.securityfocus.com/bid/37327 | vdb-entryx_refsource_BIDExploitThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2009-4427 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=549559 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2009-4427 | ||
| https://www.cve.org/CVERecord?id=CVE-2009-4427 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 28, 2009
Updated Aug 7, 2024
Reserved Dec 28, 2009
Link CVE-2009-4427
CISA Vulnrichment
Updated n/a