Apachefriends kayıtları
apachefriends üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-255 Credentials Management Errors1
- CWE-276 Incorrect Default Permissions1
- CWE-281 Improper Preservation of Permissions1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-400 Uncontrolled Resource Consumption1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2020-11107Kavram kanıtı | An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows.apachefriends · xampp · CWE-732 | Yüksek8,8 | — | %22,5 | 2 Nis 2020 |
40Planlayın | CVE-2019-8923Kavram kanıtı | XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter.apachefriends · xampp · CWE-89 | Kritik9,8 | — | %3,9 | 14 May 2019 |
39İzleyin | CVE-2024-0338İstismar yok | Buffer Overflow Vulnerability in XAMPPapachefriends · xampp · CWE-119 | Kritik9,8 | — | %0,5 | 2 Şub 2024 |
35İzleyin | CVE-2022-29376İstismar yok | Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute aapachefriends · xampp · CWE-276 | Yüksek8,8 | — | %1,4 | 23 May 2022 |
33İzleyin | CVE-2009-0919İstismar yok | XAMPP installs multiple packages with insecure default passwords, which makes it easier for remote attackers to obtain access via (1) the "lapachefriends · xampp · CWE-255 | Yüksek7,5 | — | %9,0 | 16 Mar 2009 |
31İzleyin | CVE-2017-20018İstismar yok | XAMPP Installer uncontrolled search pathapachefriends · xampp · CWE-427 | Yüksek7,8 | — | %0,6 | 9 Haz 2022 |
30İzleyin | CVE-2024-5055İstismar yok | Vulnerability of uncontrolled resource consumption in XAMPPapache friends · xampp · CWE-400 | Yüksek7,5 | — | %0,4 | 17 May 2024 |
27İzleyin | CVE-2008-6498Kavram kanıtı | Cross-site request forgery (CSRF) vulnerability in security/xamppsecurity.php in XAMPP 1.6.8 allows remote attackers to hijack the authenticapachefriends · xampp · CWE-352 | Orta6,8 | — | %1,0 | 19 Mar 2009 |
26İzleyin | CVE-2019-8924Kavram kanıtı | XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter.apachefriends · xampp · CWE-79 | Orta6,1 | — | %5,7 | 16 May 2019 |
26İzleyin | CVE-2022-47637İstismar yok | The installer in XAMPP through 8.1.12 allows local users to write to the C:\xampp directory.apachefriends · xampp · CWE-281 | Orta6,7 | — | %0,3 | 12 Eyl 2023 |
24İzleyin | CVE-2019-8920İstismar yok | iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569.apachefriends · xampp · CWE-79 | Orta6,1 | — | %0,8 | 9 Tem 2019 |
22İzleyin | CVE-2008-6499Kavram kanıtı | security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows remote attackers to spapachefriends · xampp · CWE-94 | Orta5,5 | — | %1,6 | 19 Mar 2009 |
19İzleyin | CVE-2013-2586Kavram kanıtı | XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp and execute cross-siapachefriends · xampp · CWE-79 | Orta4,3 | — | %5,2 | 29 Eyl 2014 |
18İzleyin | CVE-2006-4994İstismar yok | Multiple unquoted Windows search path vulnerabilities in Apache Friends XAMPP 1.5.2 might allow local users to gain privileges via a malicioapachefriends · xampp | Orta4,6 | — | %0,4 | 25 Eyl 2006 |
- CVE-2020-1110742Planlayın
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows.
YüksekCVSS 8,8Kavram kanıtıEPSS %22apachefriends · xampp2 Nis 2020
- CVE-2019-892340Planlayın
XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter.
KritikCVSS 9,8Kavram kanıtıEPSS %4apachefriends · xampp14 May 2019
- CVE-2024-033839İzleyin
Buffer Overflow Vulnerability in XAMPP
KritikCVSS 9,8İstismar yokEPSS %0apachefriends · xampp2 Şub 2024
- CVE-2022-2937635İzleyin
Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute a
YüksekCVSS 8,8İstismar yokEPSS %1apachefriends · xampp23 May 2022
- CVE-2009-091933İzleyin
XAMPP installs multiple packages with insecure default passwords, which makes it easier for remote attackers to obtain access via (1) the "l
YüksekCVSS 7,5İstismar yokEPSS %9apachefriends · xampp16 Mar 2009
- CVE-2017-2001831İzleyin
XAMPP Installer uncontrolled search path
YüksekCVSS 7,8İstismar yokEPSS %1apachefriends · xampp9 Haz 2022
- CVE-2024-505530İzleyin
Vulnerability of uncontrolled resource consumption in XAMPP
YüksekCVSS 7,5İstismar yokEPSS %0apache friends · xampp17 May 2024
- CVE-2008-649827İzleyin
Cross-site request forgery (CSRF) vulnerability in security/xamppsecurity.php in XAMPP 1.6.8 allows remote attackers to hijack the authentic
OrtaCVSS 6,8Kavram kanıtıEPSS %1apachefriends · xampp19 Mar 2009
- CVE-2019-892426İzleyin
XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter.
OrtaCVSS 6,1Kavram kanıtıEPSS %6apachefriends · xampp16 May 2019
- CVE-2022-4763726İzleyin
The installer in XAMPP through 8.1.12 allows local users to write to the C:\xampp directory.
OrtaCVSS 6,7İstismar yokEPSS %0apachefriends · xampp12 Eyl 2023
- CVE-2019-892024İzleyin
iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569.
OrtaCVSS 6,1İstismar yokEPSS %1apachefriends · xampp9 Tem 2019
- CVE-2008-649922İzleyin
security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows remote attackers to sp
OrtaCVSS 5,5Kavram kanıtıEPSS %2apachefriends · xampp19 Mar 2009
- CVE-2013-258619İzleyin
XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp and execute cross-si
OrtaCVSS 4,3Kavram kanıtıEPSS %5apachefriends · xampp29 Eyl 2014
- CVE-2006-499418İzleyin
Multiple unquoted Windows search path vulnerabilities in Apache Friends XAMPP 1.5.2 might allow local users to gain privileges via a malicio
OrtaCVSS 4,6İstismar yokEPSS %0apachefriends · xampp25 Eyl 2006