Phpldapadmin Project maintains a lightweight web-based LDAP directory administration tool that, despite a narrow product focus, occupies a niche role in directory-service management infrastructure and attracts significant public exploit tooling. The vendor's vulnerability profile centers on input-handling weaknesses spanning cross-site scripting, path traversal, code injection, and command injection—attack vectors endemic to web interfaces that process user-supplied LDAP queries and filesystem paths—and while a meaningful share of its disclosures reach serious severity, the durable signal is the recurring appeal to public exploit development. Defenders deploying this tool should restrict web-interface access, apply patches promptly, and monitor for abuse of its directory-query and file-access surface; live exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpldapadmin Project over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-4075HIGH The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby parameter (aka sortby variable) in | Nov 2, 2011 | 7.5 | 70 | NO | YES |
CVE-2009-4427HIGH Directory traversal vulnerability in cmd.php in phpLDAPadmin 1.1.0.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cmd parameter. | Dec 28, 2009 | 7.5 | 35 | NO | YES |
CVE-2018-12689CRITICAL phpLDAPadmin 1.2.2 allows LDAP injection via a crafted server_id parameter in a cmd.php?cmd=login_form request, or a crafted username and password in the login panel. | Jun 22, 2018 | 9.8 | 30 | NO | NO |
CVE-2017-11107MEDIUM phpLDAPadmin through 1.2.3 has XSS in htdocs/entry_chooser.php via the form, element, rdn, or container parameter. | Jul 8, 2017 | 6.1 | 29 | NO | YES |
CVE-2005-2792MEDIUM Directory traversal vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the custom_welcome_page param | Sep 2, 2005 | 5.0 | 29 | NO | YES |
CVE-2012-0834MEDIUM Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the base parame | Feb 11, 2012 | 4.3 | 27 | NO | YES |
CVE-2011-4074MEDIUM Cross-site scripting (XSS) vulnerability in cmd.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via an _debug command. | Nov 2, 2011 | 4.3 | 26 | NO | YES |
Multiple cross-site scripting (XSS) vulnerabilities in phpLDAPadmin 0.9.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dn parameter in (a) | Apr 25, 2006 | 2.6 | 25 | NO | YES |
CVE-2011-4082HIGH A local file inclusion flaw was found in the way the phpLDAPadmin before 0.9.8 processed certain values of the "Accept-Language" HTTP header. A remote attacker could use this flaw | Nov 26, 2019 | 7.5 | 24 | NO | NO |
CVE-2005-2793HIGH PHP remote file inclusion vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to execute arbitrary PHP code via the custom_welcome_page parameter. | Sep 2, 2005 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpldapadmin Project.
Media articles that mention a CVE ID that affects a product developed by Phpldapadmin Project — matched by CVE ID, not by vendor name.