CVE-2005-2792
EPSS 14.0%
Description
Directory traversal vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the custom_welcome_page parameter.
How to fix CVE-2005-2792
To remediate CVE-2005-2792, upgrade the affected package to a fixed version below.
- Debian/phpldapadmin—upgrade to 0.9.6c-7 or later
Is CVE-2005-2792 being exploited?
Moderate — EPSS is 14.0%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 0.9.6c-7