Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2011-4074Cross-site Scripting in Phpldapadmin

Severity
4.3MEDIUMNVD
EPSS
11.8%
top 6.25%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedNov 2
Latest updateMay 13

Description

Cross-site scripting (XSS) vulnerability in cmd.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via an _debug command.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/phpldapadmin< phpldapadmin 1.2.0.5-2.1 (bookworm)
Debianphpldapadmin_project/phpldapadmin< 1.2.0.5-2.1+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-prjv-38qj-jwcv: Cross-site scripting (XSS) vulnerability in cmd2022-05-13
OSV
CVE-2011-4074: Cross-site scripting (XSS) vulnerability in cmd2011-11-02

💥Exploits & PoCs

1
Exploit-DB
phpLDAPadmin 1.2.1.1 - Remote PHP Code Injection (1)2011-10-23

📋Vendor Advisories

1
Debian
CVE-2011-4074: phpldapadmin - Cross-site scripting (XSS) vulnerability in cmd.php in phpLDAPadmin 1.2.x before...2011

💬Community

1
Bugzilla
CVE-2011-4074 CVE-2011-4075 phpldapadmin: XSS and code injection vulnerabilities in <= 1.2.1.12011-10-24