wampserver records
8 published records for vendor wampserver.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 12.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-352 Cross-Site Request Forgery (CSRF)2
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2018-8817Proof of concept | Wampserver before 3.1.3 has CSRF in add_vhost.php.wampserver · wampserver · CWE-352 | High8.8 | — | 3.1% | Mar 25, 2018 |
35Monitor | CVE-2022-36565No exploit | Incorrect access control in the install directory (C:\Wamp64) of Wamp v3.2.6 and below allows authenticated attackers to execute arbitrary cwampserver · wampserver | High8.8 | — | 1.2% | Aug 30, 2022 |
30Monitor | CVE-2016-10031Proof of concept | WampServer 3.0.6 installs two services called 'wampapache' and 'wampmysqld' with weak file permissions, running with SYSTEM privileges.wampserver · wampserver · CWE-264 | High7.5 | — | 1.2% | Dec 27, 2016 |
26Monitor | CVE-2019-11517No exploit | WampServer before 3.1.9 has CSRF in add_vhost.php because the synchronizer pattern implemented as remediation of CVE-2018-8817 was incompletwampserver · wampserver · CWE-352 | Medium6.5 | — | 0.4% | Jun 10, 2019 |
24Monitor | CVE-2018-1000848No exploit | Wampserver version prior to version 3.1.5 contains a Cross Site Scripting (XSS) vulnerability in index.php localhost page that can result inwampserver · wampserver · CWE-79 | Medium6.1 | — | 0.6% | Dec 20, 2018 |
21Monitor | CVE-2018-8732Proof of concept | Cross-site scripting (XSS) vulnerability in WampServer 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the virtual_wampserver · wampserver · CWE-79 | Medium5.4 | — | 1.7% | Mar 19, 2018 |
21Monitor | CVE-2016-10072No exploit | WampServer 3.0.6 has two files called 'wampmanager.exe' and 'unins000.exe' with a weak ACL for Modify.wampserver · wampserver · CWE-264 | Medium5.3 | — | 0.5% | Dec 27, 2016 |
18Monitor | CVE-2010-0700Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in WampServer 2.0i allows remote attackers to inject arbitrary web script or HTML via wampserver · wampserver · CWE-79 | Medium4.3 | — | 1.7% | Feb 23, 2010 |
- CVE-2018-881736Monitor
Wampserver before 3.1.3 has CSRF in add_vhost.php.
HighCVSS 8.8Proof of conceptEPSS 3%wampserver · wampserverMar 25, 2018
- CVE-2022-3656535Monitor
Incorrect access control in the install directory (C:\Wamp64) of Wamp v3.2.6 and below allows authenticated attackers to execute arbitrary c
HighCVSS 8.8No exploitEPSS 1%wampserver · wampserverAug 30, 2022
- CVE-2016-1003130Monitor
WampServer 3.0.6 installs two services called 'wampapache' and 'wampmysqld' with weak file permissions, running with SYSTEM privileges.
HighCVSS 7.5Proof of conceptEPSS 1%wampserver · wampserverDec 27, 2016
- CVE-2019-1151726Monitor
WampServer before 3.1.9 has CSRF in add_vhost.php because the synchronizer pattern implemented as remediation of CVE-2018-8817 was incomplet
MediumCVSS 6.5No exploitEPSS 0%wampserver · wampserverJun 10, 2019
- CVE-2018-100084824Monitor
Wampserver version prior to version 3.1.5 contains a Cross Site Scripting (XSS) vulnerability in index.php localhost page that can result in
MediumCVSS 6.1No exploitEPSS 1%wampserver · wampserverDec 20, 2018
- CVE-2018-873221Monitor
Cross-site scripting (XSS) vulnerability in WampServer 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the virtual_
MediumCVSS 5.4Proof of conceptEPSS 2%wampserver · wampserverMar 19, 2018
- CVE-2016-1007221Monitor
WampServer 3.0.6 has two files called 'wampmanager.exe' and 'unins000.exe' with a weak ACL for Modify.
MediumCVSS 5.3No exploitEPSS 1%wampserver · wampserverDec 27, 2016
- CVE-2010-070018Monitor
Cross-site scripting (XSS) vulnerability in index.php in WampServer 2.0i allows remote attackers to inject arbitrary web script or HTML via
MediumCVSS 4.3Proof of conceptEPSS 2%wampserver · wampserverFeb 23, 2010