CORE IMPACT v12 - Exploits Update (Wed Jan 04 2012)
Phpldapadmin orderby Remote Code Execution Exploit
Exploits/Remote [Linux]
Wed Jan 04 2012
Input passed to the "orderby" parameter in cmd.php (when "cmd" is set to "query_engine", "query" is set to "none", and "search" is set to e.g. "1") is not properly sanitised in lib/functions.php before being used in a "create_function()" function call. This can be exploited to inject and execute arbitrary PHP code.
Exploits Vulnerabiltiy: CVE-2011-4075











