Nmap isn´t usefull in any shape here -

Seems that there is a possible injection, but it looks client sided..

After some research i’ve found an user - This combined with an LDAP Bypass lead to pwn !