PT-2009-1969 · Apache Friends · Xampp

Michael Brooks

·

Publicado

2009-03-20

·

Atualizado

2017-09-29

·

CVE-2008-6499

CVSS v2.0

5.5

Média

VetorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions XAMPP version 1.6.8
Description The issue allows remote attackers to spoof critical variables by performing an extract operation on the SERVER superglobal array in the security/xamppsecurity.php file. This can be demonstrated by setting the REMOTE ADDR variable to 127.0.0.1, potentially allowing attackers to manipulate the system.
Recommendations For XAMPP version 1.6.8, consider restricting access to the security/xamppsecurity.php file until a patch is available, or apply a configuration change to prevent the extract operation on the SERVER superglobal array. As a temporary workaround, avoid using the REMOTE ADDR variable in security-critical operations.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-6499

Produtos afetados

Xampp