← Back

CVE-2015-5349

nvd nist
Published: Apr 11, 2016Modified: May 6, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers to execute arbitrary commands by leveraging a crafted LDAP entry that is interpreted as a formula when imported into a spreadsheet.

Affected (27)

2 products
Ldap Studio
Directory Studio
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Version 0.6.0
Version 0.7.0
Version 0.8.0
Version 0.8.1
Configuration B
23 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Version 1.0.0
Version 1.0.1
Version 1.1.0
Version 1.1.0 rc1
Version 1.1.0 rc2
Version 1.2.0
Version 1.2.0 rc1
Version 1.3.0
Version 1.3.0 rc1
Version 1.4.0
Version 1.5.0
Version 1.5.1
Version 1.5.2
Version 1.5.3
Version 2.0.0 milestone1
Version 2.0.0 milestone2
Version 2.0.0 milestone3
Version 2.0.0 milestone4
Version 2.0.0 milestone5
Version 2.0.0 milestone6
Version 2.0.0 milestone7
Version 2.0.0 milestone8
Version 2.0.0 milestone9

Timeline

No history available yet.