Записи Apachefriends
14 опубликованных записей вендора apachefriends.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-255 Credentials Management Errors1
- CWE-276 Incorrect Default Permissions1
- CWE-281 Improper Preservation of Permissions1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-400 Uncontrolled Resource Consumption1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
14 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2020-11107Proof of concept | An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows.apachefriends · xampp · CWE-732 | Высокая8,8 | — | 22,5 % | 2 апр. 2020 г. |
40В плане | CVE-2019-8923Proof of concept | XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter.apachefriends · xampp · CWE-89 | Критическая9,8 | — | 3,9 % | 14 мая 2019 г. |
39Наблюдать | CVE-2024-0338Эксплойта нет | Buffer Overflow Vulnerability in XAMPPapachefriends · xampp · CWE-119 | Критическая9,8 | — | 0,5 % | 2 февр. 2024 г. |
35Наблюдать | CVE-2022-29376Эксплойта нет | Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute aapachefriends · xampp · CWE-276 | Высокая8,8 | — | 1,4 % | 23 мая 2022 г. |
33Наблюдать | CVE-2009-0919Эксплойта нет | XAMPP installs multiple packages with insecure default passwords, which makes it easier for remote attackers to obtain access via (1) the "lapachefriends · xampp · CWE-255 | Высокая7,5 | — | 9,0 % | 16 мар. 2009 г. |
31Наблюдать | CVE-2017-20018Эксплойта нет | XAMPP Installer uncontrolled search pathapachefriends · xampp · CWE-427 | Высокая7,8 | — | 0,6 % | 9 июн. 2022 г. |
30Наблюдать | CVE-2024-5055Эксплойта нет | Vulnerability of uncontrolled resource consumption in XAMPPapache friends · xampp · CWE-400 | Высокая7,5 | — | 0,4 % | 17 мая 2024 г. |
27Наблюдать | CVE-2008-6498Proof of concept | Cross-site request forgery (CSRF) vulnerability in security/xamppsecurity.php in XAMPP 1.6.8 allows remote attackers to hijack the authenticapachefriends · xampp · CWE-352 | Средняя6,8 | — | 1,0 % | 19 мар. 2009 г. |
26Наблюдать | CVE-2019-8924Proof of concept | XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter.apachefriends · xampp · CWE-79 | Средняя6,1 | — | 5,7 % | 16 мая 2019 г. |
26Наблюдать | CVE-2022-47637Эксплойта нет | The installer in XAMPP through 8.1.12 allows local users to write to the C:\xampp directory.apachefriends · xampp · CWE-281 | Средняя6,7 | — | 0,3 % | 12 сент. 2023 г. |
24Наблюдать | CVE-2019-8920Эксплойта нет | iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569.apachefriends · xampp · CWE-79 | Средняя6,1 | — | 0,8 % | 9 июл. 2019 г. |
22Наблюдать | CVE-2008-6499Proof of concept | security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows remote attackers to spapachefriends · xampp · CWE-94 | Средняя5,5 | — | 1,6 % | 19 мар. 2009 г. |
19Наблюдать | CVE-2013-2586Proof of concept | XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp and execute cross-siapachefriends · xampp · CWE-79 | Средняя4,3 | — | 5,2 % | 29 сент. 2014 г. |
18Наблюдать | CVE-2006-4994Эксплойта нет | Multiple unquoted Windows search path vulnerabilities in Apache Friends XAMPP 1.5.2 might allow local users to gain privileges via a malicioapachefriends · xampp | Средняя4,6 | — | 0,4 % | 25 сент. 2006 г. |
- CVE-2020-1110742В плане
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows.
ВысокаяCVSS 8,8Proof of conceptEPSS 22 %apachefriends · xampp2 апр. 2020 г.
- CVE-2019-892340В плане
XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter.
КритическаяCVSS 9,8Proof of conceptEPSS 4 %apachefriends · xampp14 мая 2019 г.
- CVE-2024-033839Наблюдать
Buffer Overflow Vulnerability in XAMPP
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %apachefriends · xampp2 февр. 2024 г.
- CVE-2022-2937635Наблюдать
Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute a
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %apachefriends · xampp23 мая 2022 г.
- CVE-2009-091933Наблюдать
XAMPP installs multiple packages with insecure default passwords, which makes it easier for remote attackers to obtain access via (1) the "l
ВысокаяCVSS 7,5Эксплойта нетEPSS 9 %apachefriends · xampp16 мар. 2009 г.
- CVE-2017-2001831Наблюдать
XAMPP Installer uncontrolled search path
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %apachefriends · xampp9 июн. 2022 г.
- CVE-2024-505530Наблюдать
Vulnerability of uncontrolled resource consumption in XAMPP
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %apache friends · xampp17 мая 2024 г.
- CVE-2008-649827Наблюдать
Cross-site request forgery (CSRF) vulnerability in security/xamppsecurity.php in XAMPP 1.6.8 allows remote attackers to hijack the authentic
СредняяCVSS 6,8Proof of conceptEPSS 1 %apachefriends · xampp19 мар. 2009 г.
- CVE-2019-892426Наблюдать
XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter.
СредняяCVSS 6,1Proof of conceptEPSS 6 %apachefriends · xampp16 мая 2019 г.
- CVE-2022-4763726Наблюдать
The installer in XAMPP through 8.1.12 allows local users to write to the C:\xampp directory.
СредняяCVSS 6,7Эксплойта нетEPSS 0 %apachefriends · xampp12 сент. 2023 г.
- CVE-2019-892024Наблюдать
iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %apachefriends · xampp9 июл. 2019 г.
- CVE-2008-649922Наблюдать
security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows remote attackers to sp
СредняяCVSS 5,5Proof of conceptEPSS 2 %apachefriends · xampp19 мар. 2009 г.
- CVE-2013-258619Наблюдать
XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp and execute cross-si
СредняяCVSS 4,3Proof of conceptEPSS 5 %apachefriends · xampp29 сент. 2014 г.
- CVE-2006-499418Наблюдать
Multiple unquoted Windows search path vulnerabilities in Apache Friends XAMPP 1.5.2 might allow local users to gain privileges via a malicio
СредняяCVSS 4,6Эксплойта нетEPSS 0 %apachefriends · xampp25 сент. 2006 г.