module
phpLDAPadmin query_engine Remote PHP Code Injection
Disclosed | Created |
---|---|
2011-10-24 | 2018-05-30 |
Disclosed
2011-10-24
Created
2018-05-30
Description
This module exploits a vulnerability in the lib/functions.php for
phpLDAPadmin versions 1.2.1.1 and earlier that allows attackers input
parsed directly to the create_function() php function. A patch was
issued that uses a whitelist regex expression to check the user supplied
input before being parsed to the create_function() call.
phpLDAPadmin versions 1.2.1.1 and earlier that allows attackers input
parsed directly to the create_function() php function. A patch was
issued that uses a whitelist regex expression to check the user supplied
input before being parsed to the create_function() call.
Authors
EgiX n0b0d13s@gmail.com
mr_me steventhomasseeley@gmail.com
TecR0c roccogiovannicalvi@gmail.com
mr_me steventhomasseeley@gmail.com
TecR0c roccogiovannicalvi@gmail.com
Platform
PHP
Architectures
php
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.