[phpldapadmin] [ phpldapadmin-Bugs-2919337 ] local file inclusion vulnerability

"SourceForge.net" <[email protected]>
Newsgroups gmane.comp.ldap.davedap
Message-ID <[email protected]>
Bugs item #2919337, was opened at 2009-12-23 00:19
Message generated for change (Comment added) made by wurley
You can respond by visiting: 
https://sourceforge.net/tracker/?func=detail&atid=498546&aid=2919337&group_id=61828

Please note that this message will contain a full copy of the comment thread,
including the initial issue submission, for this request,
not just the latest update.
Category: None
Group: None
Status: Closed
Resolution: None
Priority: 5
Private: No
Submitted By: Dmitry Butskoy (buc)
Assigned to: Nobody/Anonymous (nobody)
Summary: local file inclusion vulnerability

Initial Comment:
There is a local file inclusion vulnerability, at least  in phpldapadmin versions 1.1 and 1.2. 

Public exploit/advisory is availble:
http://www.exploit-db.com/exploits/10410

as well as a Secunia advisory:
http://secunia.com/advisories/37848/
(Note, it says that solution is upgrade to 1.2, which looks wrong. 1.2 seems to be affected as well...)

No CVE name has been assigned yet.

Please, fix it as soon as possible.


----------------------------------------------------------------------

>Comment By: Deon George (wurley)
Date: 2009-12-24 07:13

Message:
Correction ...

The current 1.2.0.4 is not affected by this vulnerability. Other 1.2.0.x
may also be unaffected, but upgrading to 1.2.0.4 is a good idea anyway.

----------------------------------------------------------------------

Comment By: Dmitry Butskoy (buc)
Date: 2009-12-24 01:00

Message:
OK

----------------------------------------------------------------------

Comment By: Dmitry Butskoy (buc)
Date: 2009-12-24 01:00

Message:
This bug has been fixed already. Please either checkout a CVS
version of phpLDAPadmin or download a developer release and try to
reproduce your bug:

http://phpldapadmin.sourceforge.net/developers.php

Thanks for the report.

----------------------------------------------------------------------

Comment By: Deon George (wurley)
Date: 2009-12-23 08:26

Message:
How is 1.2 affected? Function "isCommandAvailable()" checks to see that the
cmd is defined in the config file. So an administrator would need to
define../../etc/passwd in the config file, for it to be displayed.

----------------------------------------------------------------------

You can respond by visiting: 
https://sourceforge.net/tracker/?func=detail&atid=498546&aid=2919337&group_id=61828

------------------------------------------------------------------------------
This SF.Net email is sponsored by the Verizon Developer Community
Take advantage of Verizon's best-in-class app development support
A streamlined, 14 day to market process makes app distribution fast and easy
Join now and get one step closer to millions of Verizon customers
http://p.sf.net/sfu/verizon-dev2dev 
______________________________________
phpLDAPadmin development mailing list.
To unsbuscribe: https://lists.sourceforge.net/lists/listinfo/phpldapadmin-devel
http://phpldapadmin.sourceforge.net/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.