apachefriends
DevTools & CIcommercial
Top products
Latest CVEs
The 13 most recently published vulnerabilities affecting apachefriends.
- CVE-2024-0338Buffer Overflow Vulnerability in XAMPP7.3
- CVE-2022-47637The installer in XAMPP through 8.1.12 allows local users to write to the C:\xampp directory. Common use cases execute files under C:\xampp with administrative privileges.6.7
- CVE-2017-20018XAMPP Installer uncontrolled search path6.3
- CVE-2022-29376Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute arbitrary code via overwriting binaries located in the dir...8.8
- CVE-2020-11107An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged user can change a .exe configuration in xampp-contol.ini for all users (incl...8.8
- CVE-2019-8920iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569.6.1
- CVE-2019-8924XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued.6.1
- CVE-2019-8923XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. NOTE: This product is discontinued.9.8
- CVE-2013-2586XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp and execute cross-site scripting (XSS) attacks via the WriteIntoLocalDisk met...4.3
- CVE-2008-6498Cross-site request forgery (CSRF) vulnerability in security/xamppsecurity.php in XAMPP 1.6.8 allows remote attackers to hijack the authentication of users for requests that change a certain .htacce...6.8
- CVE-2008-6499security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows remote attackers to spoof critical variables, as demonstrated by setting the RE...5.5
- CVE-2009-0919XAMPP installs multiple packages with insecure default passwords, which makes it easier for remote attackers to obtain access via (1) the "lampp" default password for the "nobody" account within th...7.5
- CVE-2006-4994Multiple unquoted Windows search path vulnerabilities in Apache Friends XAMPP 1.5.2 might allow local users to gain privileges via a malicious program file in %SYSTEMDRIVE%, which is run when XAMPP...4.6