Apache Distribution
Xampp · 6 CVEs
The installer in XAMPP through 8.1.12 allows local users to write to the C:\xampp directory. Common use cases execute f…
Sep 12, 2023
Multiple SQL injection vulnerabilities in XAMPP 1.6.0a for Windows allow remote attackers to execute arbitrary SQL comm…
Apr 18, 2007
The ADONewConnection Connect function in adodb.php in XAMPP 1.6.0a and earlier for Windows uses untrusted input for the…
Apr 18, 2007
Directory traversal vulnerability in XAMPP before 1.4.14 allows remote attackers to inject arbitrary HTML and PHP code…
Jun 22, 2005
XAMPP 1.4.x has multiple default or null passwords, which allows attackers to gain privileges.
Apr 12, 2005
Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.4.x allow remote attackers to inject arbitrary web scrip…
Apr 12, 2005
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2022-47637 | The installer in XAMPP through 8.1.12 allows local users to write to the C:\xampp directory. Common use cases execute files under C:\xampp with administrative… | MEDIUM | 0.26% | Sep 12, 2023 |
| CVE-2007-2080 | Multiple SQL injection vulnerabilities in XAMPP 1.6.0a for Windows allow remote attackers to execute arbitrary SQL commands via unspecified vectors in certain… | HIGH | 0.97% | Apr 18, 2007 |
| CVE-2007-2079 | The ADONewConnection Connect function in adodb.php in XAMPP 1.6.0a and earlier for Windows uses untrusted input for the database server hostname, which allows… | HIGH | 9.69% | Apr 18, 2007 |
| CVE-2005-2043 | Directory traversal vulnerability in XAMPP before 1.4.14 allows remote attackers to inject arbitrary HTML and PHP code via lang.php. | MEDIUM | 1.64% | Jun 22, 2005 |
| CVE-2005-1078 | XAMPP 1.4.x has multiple default or null passwords, which allows attackers to gain privileges. | HIGH | 4.69% | Apr 12, 2005 |
| CVE-2005-1077 | Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.4.x allow remote attackers to inject arbitrary web script or HTML via (1) cds.php, (2) Guestbook… | MEDIUM | 1.75% | Apr 12, 2005 |
Showing 1 to 6 of 6 CVEs