phpldapadmin before 0.9.6c allows remote attackers to gain anonymous access to the LDAP server, even when disable_anon_bind is set, via an HTTP request to login.php with the anonymous_bind parameter set.
Link | Tags |
---|---|
http://www.debian.org/security/2005/dsa-790 | third party advisory patch vendor advisory |
http://www.gentoo.org/security/en/glsa/glsa-200509-04.xml | third party advisory vendor advisory |
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=322423 | third party advisory |