Bug#646754: Exploit in phpldapadmin lets attacker execute arbitrary code

2011-10-26 Thread Jonathan Wiltshire
On Wed, Oct 26, 2011 at 12:24:26PM -0700, John Bloom wrote: > All versions of phpldapadmin <= 1.2.1.1 (all released versions as of > today) are vulnerable to a remote code execution bug. Arbitrary code can be > executed as the user running the web server that phpldapadmin is running > under (usuall

Bug#646754: Exploit in phpldapadmin lets attacker execute arbitrary code

2011-10-26 Thread John Bloom
Package: phpldapadmin Version: 1.2.0.5-2 Severity: critical Tags: security upstream Justification: root security hole All versions of phpldapadmin <= 1.2.1.1 (all released versions as of today) are vulnerable to a remote code execution bug. Arbitrary code can be executed as the user running the we