phpldapadmin before 0.9.6c allows remote attackers to gain anonymous access to the LDAP server, even when disable_anon_bind is set, via an HTTP request to login.php with the anonymous_bind parameter set.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phpldapadmin | Phpldapadmin_project | * | 0.9.6c (excluding) |