Phpldapadmin

Vendor:

First CVE: Aug 30, 2005 · Active for 20 years

12
Total CVEs
More Total CVEs than 90% of tracked products
1.3
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Phpldapadmin over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 30, 2005
20 years ago
Most Recent CVE
Dec 11, 2020
2,051 days ago

CVE Severity & Scoring

Phpldapadmin12 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (33.3%)
Unknown8 (66.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (33.3%)
High0 (0.0%)
Unknown8 (66.7%)
User Interaction
None2 (16.7%)
Unknown8 (66.7%)
Required2 (16.7%)
Privileges Required
Low1 (8.3%)
High0 (0.0%)
None3 (25.0%)
Unknown8 (66.7%)

Top CVEs

Signals from CVEs in this product scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby parameter (aka sortby variable) in
Nov 2, 20117.570NOYES
Directory traversal vulnerability in cmd.php in phpLDAPadmin 1.1.0.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cmd parameter.
Dec 28, 20097.535NOYES
phpLDAPadmin 1.2.2 allows LDAP injection via a crafted server_id parameter in a cmd.php?cmd=login_form request, or a crafted username and password in the login panel.
Jun 22, 20189.830NONO
phpLDAPadmin through 1.2.3 has XSS in htdocs/entry_chooser.php via the form, element, rdn, or container parameter.
Jul 8, 20176.129NOYES
Directory traversal vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the custom_welcome_page param
Sep 2, 20055.029NOYES
Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the base parame
Feb 11, 20124.327NOYES
Cross-site scripting (XSS) vulnerability in cmd.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via an _debug command.
Nov 2, 20114.326NOYES
Multiple cross-site scripting (XSS) vulnerabilities in phpLDAPadmin 0.9.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dn parameter in (a)
Apr 25, 20062.625NOYES
A local file inclusion flaw was found in the way the phpLDAPadmin before 0.9.8 processed certain values of the "Accept-Language" HTTP header. A remote attacker could use this flaw
Nov 26, 20197.524NONO
PHP remote file inclusion vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to execute arbitrary PHP code via the custom_welcome_page parameter.
Sep 2, 20057.522NONO

Exploit Exposure

Signals from CVEs in this product scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
8.3% of CVEs· 97th percentile
Nuclei
1 CVE
8.3% of CVEs· 97th percentile
ExploitDB
6 CVEs
50.0% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (12 CVEs).

Media Mentions

Signals from CVEs in this product scope (12 CVEs).

Top CNAs Publishing CVEs For Phpldapadmin

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.2.219.81.8%00
1.2.1.125.928.2%02
1.2.125.928.2%02
1.2.0.525.928.2%02
1.2.0.425.928.2%02
1.2.0.325.928.2%02
1.2.0.225.928.2%02
1.2.0.125.928.2%02
1.2.025.928.2%02
1.1.0.517.510.0%01
0.9.726.37.2%01
0.9.626.37.2%01