CVE-2012-10062
- EPSS 53.87%
- Veröffentlicht 30.08.2025 13:57:30
- Zuletzt bearbeitet 02.09.2025 15:55:25
A vulnerability in XAMPP, developed by Apache Friends, version 1.7.3's default WebDAV configuration allows remote authenticated attackers to upload and execute arbitrary PHP code. The WebDAV service, accessible via /webdav/, accepts HTTP PUT requests...
CVE-2024-5055
- EPSS 0.17%
- Veröffentlicht 17.05.2024 12:15:18
- Zuletzt bearbeitet 21.11.2024 09:46:52
Uncontrolled resource consumption vulnerability in XAMPP Windows, versions 7.3.2 and earlier. This vulnerability exists when XAMPP attempts to process many incomplete HTTP requests, resulting in resource consumption and system crashes.
CVE-2024-0338
- EPSS 0.1%
- Veröffentlicht 02.02.2024 10:15:08
- Zuletzt bearbeitet 21.11.2024 08:46:20
A buffer overflow vulnerability has been found in XAMPP affecting version 8.2.4 and earlier. An attacker could execute arbitrary code through a long file debug argument that controls the Structured Exception Handler (SEH).
CVE-2022-47637
- EPSS 0.06%
- Veröffentlicht 12.09.2023 22:15:07
- Zuletzt bearbeitet 21.11.2024 07:32:18
The installer in XAMPP through 8.1.12 allows local users to write to the C:\xampp directory. Common use cases execute files under C:\xampp with administrative privileges.
CVE-2017-20018
- EPSS 0.25%
- Veröffentlicht 09.06.2022 23:15:07
- Zuletzt bearbeitet 21.11.2024 03:22:27
A vulnerability was found in XAMPP 7.1.1-0-VC14. It has been classified as problematic. Affected is an unknown function of the component Installer. The manipulation leads to privilege escalation. It is possible to launch the attack remotely.
CVE-2022-29376
- EPSS 0.58%
- Veröffentlicht 23.05.2022 21:16:05
- Zuletzt bearbeitet 15.08.2025 15:15:28
Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute arbitrary code via overwriting binaries located in the directory.
CVE-2020-11107
- EPSS 33.3%
- Veröffentlicht 02.04.2020 18:15:18
- Zuletzt bearbeitet 21.11.2024 04:56:48
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged user can change a .exe configuration in xampp-contol.ini for all users (including admins) to enable arbitrary command execution.
CVE-2019-8920
- EPSS 0.24%
- Veröffentlicht 09.07.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:50:39
iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569.
CVE-2019-8924
- EPSS 2.28%
- Veröffentlicht 17.05.2019 02:29:00
- Zuletzt bearbeitet 21.11.2024 04:50:40
XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued.
CVE-2019-8923
- EPSS 12.41%
- Veröffentlicht 14.05.2019 16:29:02
- Zuletzt bearbeitet 21.11.2024 04:50:39
XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. NOTE: This product is discontinued.