4.3
CVSSv2

CVE-2013-2586

Published: 29/09/2014 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote malicious users to modify xampp/lang.tmp and execute cross-site scripting (XSS) attacks via the WriteIntoLocalDisk method.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apachefriends xampp 1.8.1

Exploits

============================================= INTERNET SECURITY AUDITORS ALERT 2013-007 - Original release date: March 14th, 2013 - Last revised: March 19th, 2013 - Discovered by: Manuel García Cárdenas - Severity: 6,8/10 (CVSS Base Score) - CVE-ID: CVE-2013-2586 ============================================= I VULNERABILITY ------------------- ...
XAMPP version 181 allows an unprivileged user the ability to write to the local disk ...