bugs.launchpad.net
https://bugs.launchpad.net/ubuntu/+source/phpldapadmin/+bug/1701731 CVE-2017-11107
MEDIUMNuclei
phpLDAPadmin <= 1.2.3 - Reflected XSS
Record summary
CVE-2017-11107 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
phpLDAPadmin through 1.2.3 has XSS in htdocs/entry_chooser.php via the form, element, rdn, or container parameter.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMphpLDAPadmin <= 1.2.3 - Reflected XSSCVSS 6.1
phpLDAPadmin <= 1.2.3 contains a reflected cross-site scripting caused by unsanitized input in htdocs/entry_chooser.php via the form, element, rdn, or container parameter, letting attackers execute malicious scripts in victim browsers, exploit requires sending crafted input.
Impact
Attackers can execute malicious scripts in victim browsers, potentially leading to session hijacking or defacement.
Remediation
Update to the latest version of phpLDAPadmin where the vulnerability is fixed.
WeaknessesCWE-79
Authors0x_Akoko
Template tagscvecve2017phpldapadminxssunauth
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:phpldapadmin_project:phpldapadmin:*:*:*:*:*:*:*:*
Shodan: html:"phpLDAPadmin"
https://nvd.nist.gov/vuln/detail/CVE-2017-11107 https://github.com/leenooks/phpLDAPadmin/issues/50 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=867719
Source: ProjectDiscovery
References
4github.com
https://github.com/leenooks/phpLDAPadmin/issues/50 [debian-lts-announce] 20181031 [SECURITY] [DLA 1561-1] phpldapadmin security updatemailing list
https://lists.debian.org/debian-lts-announce/2018/10/msg00023.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-11107