phpldapadmin before 0.9.6c allows remote attackers to gain anonymous access to the LDAP server, even when disable_anon_bind is set, via an HTTP request to login.php with the anonymous_bind parameter set.
References
Link | Resource |
---|---|
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=322423 | Third Party Advisory |
http://www.debian.org/security/2005/dsa-790 | Patch Third Party Advisory |
http://www.gentoo.org/security/en/glsa/glsa-200509-04.xml | Third Party Advisory |
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=322423 | Third Party Advisory |
http://www.debian.org/security/2005/dsa-790 | Patch Third Party Advisory |
http://www.gentoo.org/security/en/glsa/glsa-200509-04.xml | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2005-08-30 17:03
Updated : 2025-04-03 01:03
NVD link : CVE-2005-2654
Mitre link : CVE-2005-2654
CVE.ORG link : CVE-2005-2654
JSON object : View
Products Affected
phpldapadmin_project
- phpldapadmin
CWE