CVE Browser

More filters (active)
CVE-2024-9102 MEDIUM

phpLDAPadmin: Improper Neutralization of Formula Elements

CVSS 5.0 EPSS 0.42% Dec 19, 2024
CVE-2024-9101 LOW

phpLDAPadmin: Reflected Cross-Site Scripting in entry_chooser.php

CVSS 2.1 EPSS 0.50% Dec 19, 2024
CVE-2020-35132 MEDIUM

An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be executed by other users at a later time…

CVSS 5.4 EPSS 1.25% Dec 11, 2020
CVE-2011-4082 HIGH

A local file inclusion flaw was found in the way the phpLDAPadmin before 0.9.8 processed certain values of the "Accept-Language" HTTP header. A remote attacker…

CVSS 7.5 EPSS 1.69% Nov 26, 2019
CVE-2018-12689 CRITICAL

phpLDAPadmin 1.2.2 allows LDAP injection via a crafted server_id parameter in a cmd.php?cmd=login_form request, or a crafted username and password in the login…

CVSS 9.8 EPSS 1.78% Jun 22, 2018
CVE-2017-11107 MEDIUM

phpLDAPadmin through 1.2.3 has XSS in htdocs/entry_chooser.php via the form, element, rdn, or container parameter.

CVSS 6.1 EPSS 2.07% Jul 8, 2017
CVE-2012-0834 MEDIUM

Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTM…

CVSS 4.3 EPSS 4.79% Feb 11, 2012
CVE-2011-4075 HIGH

The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby parameter (ak…

CVSS 7.5 EPSS 51.89% Nov 2, 2011
CVE-2011-4074 MEDIUM

Cross-site scripting (XSS) vulnerability in cmd.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via an _d…

CVSS 4.3 EPSS 5.39% Nov 2, 2011
CVE-2009-4427 HIGH

phpldapadmin: local file inclusion vulnerability

CVSS 7.5 EPSS 10.00% Dec 28, 2009
CVE-2006-2016 LOW

Multiple cross-site scripting (XSS) vulnerabilities in phpLDAPadmin 0.9.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1)…

CVSS 2.6 EPSS 8.22% Apr 25, 2006
CVE-2005-2793 HIGH

PHP remote file inclusion vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to execute arbitrary PHP code via the custom_wel…

CVSS 7.5 EPSS 2.74% Sep 2, 2005
CVE-2005-2792 MEDIUM

Directory traversal vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the cust…

CVSS 5.0 EPSS 11.67% Sep 2, 2005
CVE-2005-2654 HIGH

phpldapadmin before 0.9.6c allows remote attackers to gain anonymous access to the LDAP server, even when disable_anon_bind is set, via an HTTP request to logi…

CVSS 7.5 EPSS 1.78% Aug 30, 2005

Showing 1 to 14 CVEs · page 1