Mandriva Linux Security Advisory 2010-023 – Directory traversal vulnerability in cmd.php in phpLDAPadmin 1.1.0.5 allows remote attackers to include and execute arbitrary local files via a. (dot dot) in the cmd parameter. The updated packages have been patched to correct this issue.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/85512/MDVSA-2010-023.txt
Source: https://packetstormsecurity.com/files/85512/Mandriva-Linux-Security-Advisory-2010-023.html

