4.6
CVE-2006-4994
- EPSS 0.37%
- Veröffentlicht 26.09.2006 02:07:00
- Zuletzt bearbeitet 16.06.2026 22:30:16
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple unquoted Windows search path vulnerabilities in Apache Friends XAMPP 1.5.2 might allow local users to gain privileges via a malicious program file in %SYSTEMDRIVE%, which is run when XAMPP attempts to execute (1) FileZillaServer.exe, (2) mysqld-nt.exe, (3) Perl.exe, or (4) xamppcontrol.exe with an unquoted "Program Files" pathname.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apachefriends ≫ Xampp Version1.5.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.37% | 0.285 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
http://lists.grok.org.uk/pipermail/full-disclosure/2006-May/046218.html
http://secdev.zoller.lu/research/xamp1.htm
http://www.apachefriends.org/en/news-article%2C75557.html
http://www.securityfocus.com/archive/1/434699/30/4860/threaded
https://exchange.xforce.ibmcloud.com/vulnerabilities/26581