Phpldapadmin
Vendor:
First CVE: Aug 30, 2005 · Active for 20 years
12
Total CVEs
More Total CVEs than 90% of tracked products
1.3
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Phpldapadmin over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 30, 2005
20 years ago
Most Recent CVE
Dec 11, 2020
2,051 days ago
CVE Severity & Scoring
Phpldapadmin12 CVEs
8%
42%
42%
8%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (33.3%)
Unknown8 (66.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (33.3%)
High0 (0.0%)
Unknown8 (66.7%)
User Interaction
None2 (16.7%)
Unknown8 (66.7%)
Required2 (16.7%)
Privileges Required
Low1 (8.3%)
High0 (0.0%)
None3 (25.0%)
Unknown8 (66.7%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-4075HIGH The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby parameter (aka sortby variable) in | Nov 2, 2011 | 7.5 | 70 | NO | YES |
CVE-2009-4427HIGH Directory traversal vulnerability in cmd.php in phpLDAPadmin 1.1.0.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cmd parameter. | Dec 28, 2009 | 7.5 | 35 | NO | YES |
CVE-2018-12689CRITICAL phpLDAPadmin 1.2.2 allows LDAP injection via a crafted server_id parameter in a cmd.php?cmd=login_form request, or a crafted username and password in the login panel. | Jun 22, 2018 | 9.8 | 30 | NO | NO |
CVE-2017-11107MEDIUM phpLDAPadmin through 1.2.3 has XSS in htdocs/entry_chooser.php via the form, element, rdn, or container parameter. | Jul 8, 2017 | 6.1 | 29 | NO | YES |
CVE-2005-2792MEDIUM Directory traversal vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the custom_welcome_page param | Sep 2, 2005 | 5.0 | 29 | NO | YES |
CVE-2012-0834MEDIUM Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the base parame | Feb 11, 2012 | 4.3 | 27 | NO | YES |
CVE-2011-4074MEDIUM Cross-site scripting (XSS) vulnerability in cmd.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via an _debug command. | Nov 2, 2011 | 4.3 | 26 | NO | YES |
Multiple cross-site scripting (XSS) vulnerabilities in phpLDAPadmin 0.9.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dn parameter in (a) | Apr 25, 2006 | 2.6 | 25 | NO | YES |
CVE-2011-4082HIGH A local file inclusion flaw was found in the way the phpLDAPadmin before 0.9.8 processed certain values of the "Accept-Language" HTTP header. A remote attacker could use this flaw | Nov 26, 2019 | 7.5 | 24 | NO | NO |
CVE-2005-2793HIGH PHP remote file inclusion vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to execute arbitrary PHP code via the custom_welcome_page parameter. | Sep 2, 2005 | 7.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
8.3% of CVEs· 97th percentile
Nuclei
1 CVE
8.3% of CVEs· 97th percentile
ExploitDB
6 CVEs
50.0% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Phpldapadmin
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.2.2 | 1 | 9.8 | 1.8% | 0 | 0 |
| 1.2.1.1 | 2 | 5.9 | 28.2% | 0 | 2 |
| 1.2.1 | 2 | 5.9 | 28.2% | 0 | 2 |
| 1.2.0.5 | 2 | 5.9 | 28.2% | 0 | 2 |
| 1.2.0.4 | 2 | 5.9 | 28.2% | 0 | 2 |
| 1.2.0.3 | 2 | 5.9 | 28.2% | 0 | 2 |
| 1.2.0.2 | 2 | 5.9 | 28.2% | 0 | 2 |
| 1.2.0.1 | 2 | 5.9 | 28.2% | 0 | 2 |
| 1.2.0 | 2 | 5.9 | 28.2% | 0 | 2 |
| 1.1.0.5 | 1 | 7.5 | 10.0% | 0 | 1 |
| 0.9.7 | 2 | 6.3 | 7.2% | 0 | 1 |
| 0.9.6 | 2 | 6.3 | 7.2% | 0 | 1 |