| Name | CVE-2005-2792 | 
| Description | Directory traversal vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the custom_welcome_page parameter. | 
| Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) | 
| Debian Bugs | 325785 | 
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status | 
|---|
| phpldapadmin (PTS) | bookworm | 1.2.6.3-0.3+deb12u1 | fixed | 
|  | forky, sid, trixie | 1.2.6.7-4 | fixed | 
The information below is based on the following data on fixed versions.
Notes
[sarge] - phpldapadmin <not-affected> (code not present in sarge)
- egroupware <not-affected> (copy included is older and not vulnerable; bug #339583)