_______________________________________________________________________
Package : phpldapadmin
Date : January 21, 2010
Affected: Enterprise Server 5.0
_______________________________________________________________________
Problem Description:
A vulnerability has been found and corrected in phpldapadmin:
Directory traversal vulnerability in cmd.php in phpLDAPadmin 1.1.0.5
allows remote attackers to include and execute arbitrary local files
via a .. (dot dot) in the cmd parameter (CVE-2009-4427).
The updated packages have been patched to correct thies issue.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cg ... -2009-4427
_______________________________________________________________________