CVE-2011-4075

The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby...

Basic Information

CVE State
PUBLISHED
Reserved Date
October 18, 2011
Published Date
November 02, 2011
Last Updated
August 06, 2024
Vendor
phpLDAPadmin
Product
phpLDAPadmin
Description
The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby parameter (aka sortby variable) in a query_engine action to cmd.php, as exploited in the wild in October 2011.
Tags
php metasploit_scanner

CVSS Scores

CVSS v2.0

7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Exploit Status

Exploited in the Wild
Yes (2011-11-02 17:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CVE 2011-11-02 17:00:00 UTC

Scanner Integrations

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

phpldapadmin_query_engine

Type: metasploit • Created: Unknown

Metasploit module for CVE-2011-4075

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Metasploit