CVE-2012-0834

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
11/02/2012
Last modified:
13/02/2023

Description

Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the base parameter in a query_engine action to cmd.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:phpldapadmin_project:phpldapadmin:*:*:*:*:*:*:*:* 1.2.2 (including)