CVE-2011-4074
phpldapadmin - several issues
EPSS 11.8%
Description
Cross-site scripting (XSS) vulnerability in cmd.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via an _debug command.
How to fix CVE-2011-4074
To remediate CVE-2011-4074, upgrade the affected package to a fixed version below.
- Debian/phpldapadmin—upgrade to 1.2.0.5-2.1 or later
- Debian/phpldapadmin—upgrade to 1.2.0.5-2+squeeze1 or later
Is CVE-2011-4074 being exploited?
Moderate — EPSS is 11.8%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 1.2.0.5-2.1
- from 0, < 1.2.0.5-2+squeeze1