CVE-2012-0834: XSS
Published Feb 11, 2012
·Updated
Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the base parameter in a queryengine action to cmd.php.
Affected Software
1 affected component
Phpldapadmin Project Phpldapadmin<=1.2.2
Event History
Feb 11, 2012
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0834?
CVE-2012-0834 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2012-0834?
To fix CVE-2012-0834, upgrade phpLDAPadmin to version 1.2.3 or later.
3
What types of attacks can CVE-2012-0834 lead to?
CVE-2012-0834 can lead to cross-site scripting (XSS) attacks allowing attackers to inject arbitrary web scripts.
4
Which versions of phpLDAPadmin are affected by CVE-2012-0834?
CVE-2012-0834 affects phpLDAPadmin versions 1.2.2 and earlier.
5
Where does the vulnerability CVE-2012-0834 occur in the code?
CVE-2012-0834 occurs in lib/QueryRender.php specifically through the base parameter in a query_engine action.