Apachefriends records
14 published records for vendor apachefriends.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-255 Credentials Management Errors1
- CWE-276 Incorrect Default Permissions1
- CWE-281 Improper Preservation of Permissions1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-400 Uncontrolled Resource Consumption1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2020-11107Proof of concept | An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows.apachefriends · xampp · CWE-732 | High8.8 | — | 22.5% | Apr 2, 2020 |
40Plan | CVE-2019-8923Proof of concept | XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter.apachefriends · xampp · CWE-89 | Critical9.8 | — | 3.9% | May 14, 2019 |
39Monitor | CVE-2024-0338No exploit | Buffer Overflow Vulnerability in XAMPPapachefriends · xampp · CWE-119 | Critical9.8 | — | 0.5% | Feb 2, 2024 |
35Monitor | CVE-2022-29376No exploit | Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute aapachefriends · xampp · CWE-276 | High8.8 | — | 1.4% | May 23, 2022 |
33Monitor | CVE-2009-0919No exploit | XAMPP installs multiple packages with insecure default passwords, which makes it easier for remote attackers to obtain access via (1) the "lapachefriends · xampp · CWE-255 | High7.5 | — | 9.0% | Mar 16, 2009 |
31Monitor | CVE-2017-20018No exploit | XAMPP Installer uncontrolled search pathapachefriends · xampp · CWE-427 | High7.8 | — | 0.6% | Jun 9, 2022 |
30Monitor | CVE-2024-5055No exploit | Vulnerability of uncontrolled resource consumption in XAMPPapache friends · xampp · CWE-400 | High7.5 | — | 0.4% | May 17, 2024 |
27Monitor | CVE-2008-6498Proof of concept | Cross-site request forgery (CSRF) vulnerability in security/xamppsecurity.php in XAMPP 1.6.8 allows remote attackers to hijack the authenticapachefriends · xampp · CWE-352 | Medium6.8 | — | 1.0% | Mar 19, 2009 |
26Monitor | CVE-2019-8924Proof of concept | XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter.apachefriends · xampp · CWE-79 | Medium6.1 | — | 5.7% | May 16, 2019 |
26Monitor | CVE-2022-47637No exploit | The installer in XAMPP through 8.1.12 allows local users to write to the C:\xampp directory.apachefriends · xampp · CWE-281 | Medium6.7 | — | 0.3% | Sep 12, 2023 |
24Monitor | CVE-2019-8920No exploit | iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569.apachefriends · xampp · CWE-79 | Medium6.1 | — | 0.8% | Jul 9, 2019 |
22Monitor | CVE-2008-6499Proof of concept | security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows remote attackers to spapachefriends · xampp · CWE-94 | Medium5.5 | — | 1.6% | Mar 19, 2009 |
19Monitor | CVE-2013-2586Proof of concept | XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp and execute cross-siapachefriends · xampp · CWE-79 | Medium4.3 | — | 5.2% | Sep 29, 2014 |
18Monitor | CVE-2006-4994No exploit | Multiple unquoted Windows search path vulnerabilities in Apache Friends XAMPP 1.5.2 might allow local users to gain privileges via a malicioapachefriends · xampp | Medium4.6 | — | 0.4% | Sep 25, 2006 |
- CVE-2020-1110742Plan
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows.
HighCVSS 8.8Proof of conceptEPSS 22%apachefriends · xamppApr 2, 2020
- CVE-2019-892340Plan
XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter.
CriticalCVSS 9.8Proof of conceptEPSS 4%apachefriends · xamppMay 14, 2019
- CVE-2024-033839Monitor
Buffer Overflow Vulnerability in XAMPP
CriticalCVSS 9.8No exploitEPSS 0%apachefriends · xamppFeb 2, 2024
- CVE-2022-2937635Monitor
Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute a
HighCVSS 8.8No exploitEPSS 1%apachefriends · xamppMay 23, 2022
- CVE-2009-091933Monitor
XAMPP installs multiple packages with insecure default passwords, which makes it easier for remote attackers to obtain access via (1) the "l
HighCVSS 7.5No exploitEPSS 9%apachefriends · xamppMar 16, 2009
- CVE-2017-2001831Monitor
XAMPP Installer uncontrolled search path
HighCVSS 7.8No exploitEPSS 1%apachefriends · xamppJun 9, 2022
- CVE-2024-505530Monitor
Vulnerability of uncontrolled resource consumption in XAMPP
HighCVSS 7.5No exploitEPSS 0%apache friends · xamppMay 17, 2024
- CVE-2008-649827Monitor
Cross-site request forgery (CSRF) vulnerability in security/xamppsecurity.php in XAMPP 1.6.8 allows remote attackers to hijack the authentic
MediumCVSS 6.8Proof of conceptEPSS 1%apachefriends · xamppMar 19, 2009
- CVE-2019-892426Monitor
XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter.
MediumCVSS 6.1Proof of conceptEPSS 6%apachefriends · xamppMay 16, 2019
- CVE-2022-4763726Monitor
The installer in XAMPP through 8.1.12 allows local users to write to the C:\xampp directory.
MediumCVSS 6.7No exploitEPSS 0%apachefriends · xamppSep 12, 2023
- CVE-2019-892024Monitor
iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569.
MediumCVSS 6.1No exploitEPSS 1%apachefriends · xamppJul 9, 2019
- CVE-2008-649922Monitor
security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows remote attackers to sp
MediumCVSS 5.5Proof of conceptEPSS 2%apachefriends · xamppMar 19, 2009
- CVE-2013-258619Monitor
XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp and execute cross-si
MediumCVSS 4.3Proof of conceptEPSS 5%apachefriends · xamppSep 29, 2014
- CVE-2006-499418Monitor
Multiple unquoted Windows search path vulnerabilities in Apache Friends XAMPP 1.5.2 might allow local users to gain privileges via a malicio
MediumCVSS 4.6No exploitEPSS 0%apachefriends · xamppSep 25, 2006