'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:LDAP Injection Attack (by Alonso Parada)
Severity:critical
CVE ID:
| Descripiton:
|
LDAP(Lightweight Directory Access Protocol) is an open, vendor-neutral, industry standard application procotol for accessing and maintaining distributed directory information services over an Internet Protocol network. LDAP injection is a code injection technique used to exploit Web applications which would reveal sensitive user information or modify information represented in the LDAP data stores. LDAP injection exploits a security vulnerability in an application by manipulating input parameters passed to internal search, add or modify functions. When an application fails to properly sanitize user input, it is possible for an attacker to modify a LDAP statement. This rule will inspect the LDAP keywords in HTTP request to prevent LDAP injection. This rule supports to defend the A3: Injection of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.