Vulnerabilities > Apachefriends > Xampp > 1.6.8

DATE CVE VULNERABILITY TITLE RISK
2009-03-20 CVE-2008-6499 Code Injection vulnerability in Apachefriends Xampp 1.6.8
security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows remote attackers to spoof critical variables, as demonstrated by setting the REMOTE_ADDR variable to 127.0.0.1.
network
low complexity
apachefriends CWE-94
5.5
2009-03-20 CVE-2008-6498 Cross-Site Request Forgery (CSRF) vulnerability in Apachefriends Xampp 1.6.8
Cross-site request forgery (CSRF) vulnerability in security/xamppsecurity.php in XAMPP 1.6.8 allows remote attackers to hijack the authentication of users for requests that change a certain .htaccess password via the xampppasswd parameter.
6.8
2009-03-16 CVE-2009-0919 Credentials Management vulnerability in Apachefriends Xampp
XAMPP installs multiple packages with insecure default passwords, which makes it easier for remote attackers to obtain access via (1) the "lampp" default password for the "nobody" account within the included ProFTPD installation, (2) a blank default password for the "root" account within the included MySQL installation, (3) a blank default password for the "pma" account within the phpMyAdmin installation, and possibly other unspecified passwords.
network
low complexity
apachefriends CWE-255
7.5