Phpldapadmin Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 12
    Known Exploited: 0
    1
    Critical Level Threats
    5
    High Level Threats
    5
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2020-35132

    An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.

    Last Modified: Nov 21, 2024
    Published: Dec 11, 2020

    CVE-2011-4082

    A local file inclusion flaw was found in the way the phpLDAPadmin before 0.9.8 processed certain values of the "Accept-Language" HTTP header. A remote attacker could use this flaw to cause a denial of service via specially-crafted request.

    Last Modified: Nov 21, 2024
    Published: Nov 26, 2019

    CVE-2018-12689

    phpLDAPadmin 1.2.2 allows LDAP injection via a crafted server_id parameter in a cmd.php?cmd=login_form request, or a crafted username and password in the login panel.

    Last Modified: Nov 21, 2024
    Published: Jun 22, 2018

    CVE-2017-11107

    phpLDAPadmin through 1.2.3 has XSS in htdocs/entry_chooser.php via the form, element, rdn, or container parameter.

    Last Modified: Apr 20, 2025
    Published: Jul 08, 2017

    CVE-2012-0834

    Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the base parameter in a query_engine action to cmd.php.

    Last Modified: Apr 11, 2025
    Published: Feb 11, 2012
    Items Per Page
    Phpldapadmin_Project Vulnerabilities & Security CVEs | CVE-DB