apachefriends vulnerabilities and exploits

4.3
CVSSv2
CVE-2013-2586

XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp and execute cross-site scripting (XSS) attacks via the WriteIntoLocalDisk method....

ApachefriendsXampp
4.3
CVSSv2
CVE-2019-8920

iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569....

4.3
CVSSv2
CVE-2019-8924

XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued....

ApachefriendsXampp
7.5
CVSSv2
CVE-2019-8923

XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. NOTE: This product is discontinued....

ApachefriendsXampp
7.5
CVSSv2
CVE-2009-0919

XAMPP installs multiple packages with insecure default passwords, which makes it easier for remote attackers to obtain access via (1) the "lampp" default password for the "nobody" account within the included ProFTPD installation, (2) a blank default password...

5.5
CVSSv2
CVE-2008-6499

security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows remote attackers to spoof critical variables, as demonstrated by setting the REMOTE_ADDR variable to 127.0.0.1....

ApachefriendsXampp
6.8
CVSSv2
CVE-2008-6498

Cross-site request forgery (CSRF) vulnerability in security/xamppsecurity.php in XAMPP 1.6.8 allows remote attackers to hijack the authentication of users for requests that change a certain .htaccess password via the xampppasswd parameter....

ApachefriendsXampp