CVE-2022-36565
- EPSS 0.84%
- Veröffentlicht 30.08.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 07:13:19
Incorrect access control in the install directory (C:\Wamp64) of Wamp v3.2.6 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory.
CVE-2019-11517
- EPSS 0.12%
- Veröffentlicht 10.06.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:21:16
WampServer before 3.1.9 has CSRF in add_vhost.php because the synchronizer pattern implemented as remediation of CVE-2018-8817 was incomplete. An attacker could add/delete any vhosts without the consent of the owner.
CVE-2018-1000848
- EPSS 0.24%
- Veröffentlicht 20.12.2018 15:29:02
- Zuletzt bearbeitet 21.11.2024 03:40:29
Wampserver version prior to version 3.1.5 contains a Cross Site Scripting (XSS) vulnerability in index.php localhost page that can result in very low. This attack appear to be exploitable via payload onmouseover. This vulnerability appears to have be...
CVE-2018-8817
- EPSS 0.43%
- Veröffentlicht 25.03.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:22
Wampserver before 3.1.3 has CSRF in add_vhost.php.
CVE-2018-8732
- EPSS 0.17%
- Veröffentlicht 19.03.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:13
Cross-site scripting (XSS) vulnerability in WampServer 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the virtual_del parameter.
CVE-2016-10031
- EPSS 0.29%
- Veröffentlicht 27.12.2016 07:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
WampServer 3.0.6 installs two services called 'wampapache' and 'wampmysqld' with weak file permissions, running with SYSTEM privileges. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated p...
CVE-2016-10072
- EPSS 0.19%
- Veröffentlicht 27.12.2016 07:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
WampServer 3.0.6 has two files called 'wampmanager.exe' and 'unins000.exe' with a weak ACL for Modify. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system. To prope...
CVE-2010-0700
- EPSS 4.09%
- Veröffentlicht 23.02.2010 20:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in index.php in WampServer 2.0i allows remote attackers to inject arbitrary web script or HTML via the lang parameter.