Family: CGI abuses --> Category: infos
eLDAPo cleartext passwords Vulnerability Scan
Vulnerability Scan Summary
Checks for eLDAPo
Detailed Explanation for this Vulnerability Test
The remote host is hosting eLDAPo, a PHP-based CGI
suite designed to perform LDAP queries.
This application stores the passwords to the LDAP server
in clear text in its source file. A possible hacker could read
the source code of index.php and may use the information
contained to gain credentials on a third party server.
Solution : Upgrade to eLDAPo 1.18 or newer
Threat Level: Medium
Click HERE for more information and discussions on this network vulnerability scan.