CVE-2005-2792

Properties

Published:
01.09.2005
Updated:
20.10.2005
Patch available:
Severity:
Low
  • CVSS vector:
    (AV:R/AC:L/Au:NR/C:C/I:N/A:N/B:N) Approximated
    Product:
    phpldapadmin: phpldapadmin
    phpldapadmin: phpldapadmin

    Vulnerability description

    Directory traversal vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the custom_welcome_page parameter.

    References:

    BUGTRAQ: http://marc.theaimsgroup.com/?l=bugtraq&m=112542447219235&w=2
    http://www.rgod.altervista.org/phpldap.html: http://www.rgod.altervista.org/phpldap.html
    BID: http://www.securityfocus.com/bid/14695
    SECUNIA: http://secunia.com/advisories/16617/
    XF: http://xforce.iss.net/xforce/xfdb/22103
    BUGTRAQ: http://marc.theaimsgroup.com/?l=bugtraq&m=112542447219235&w=2