Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
SHARE

CORE IMPACT v12 - Exploits Update (Wed Jan 04 2012)

Phpldapadmin orderby Remote Code Execution Exploit

Exploits/Remote  [Linux]




Wed Jan 04 2012
Input passed to the "orderby" parameter in cmd.php (when "cmd" is set to "query_engine", "query" is set to "none", and "search" is set to e.g. "1") is not properly sanitised in lib/functions.php before being used in a "create_function()" function call. This can be exploited to inject and execute arbitrary PHP code.

Exploits Vulnerabiltiy: CVE-2011-4075



< Back to Product Updates