Skip to content
Noroxi

wampserver records

8 published records for vendor wampserver.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
12.5%
Median publish → KEV
No record has entered KEV

All records

8 records
  • CVE-2018-8817
    36Monitor

    Wampserver before 3.1.3 has CSRF in add_vhost.php.

    HighCVSS 8.8Proof of conceptEPSS 3%

    wampserver · wampserverMar 25, 2018

  • Incorrect access control in the install directory (C:\Wamp64) of Wamp v3.2.6 and below allows authenticated attackers to execute arbitrary c

    HighCVSS 8.8No exploitEPSS 1%

    wampserver · wampserverAug 30, 2022

  • WampServer 3.0.6 installs two services called 'wampapache' and 'wampmysqld' with weak file permissions, running with SYSTEM privileges.

    HighCVSS 7.5Proof of conceptEPSS 1%

    wampserver · wampserverDec 27, 2016

  • WampServer before 3.1.9 has CSRF in add_vhost.php because the synchronizer pattern implemented as remediation of CVE-2018-8817 was incomplet

    MediumCVSS 6.5No exploitEPSS 0%

    wampserver · wampserverJun 10, 2019

  • Wampserver version prior to version 3.1.5 contains a Cross Site Scripting (XSS) vulnerability in index.php localhost page that can result in

    MediumCVSS 6.1No exploitEPSS 1%

    wampserver · wampserverDec 20, 2018

  • CVE-2018-8732
    21Monitor

    Cross-site scripting (XSS) vulnerability in WampServer 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the virtual_

    MediumCVSS 5.4Proof of conceptEPSS 2%

    wampserver · wampserverMar 19, 2018

  • WampServer 3.0.6 has two files called 'wampmanager.exe' and 'unins000.exe' with a weak ACL for Modify.

    MediumCVSS 5.3No exploitEPSS 1%

    wampserver · wampserverDec 27, 2016

  • CVE-2010-0700
    18Monitor

    Cross-site scripting (XSS) vulnerability in index.php in WampServer 2.0i allows remote attackers to inject arbitrary web script or HTML via

    MediumCVSS 4.3Proof of conceptEPSS 2%

    wampserver · wampserverFeb 23, 2010