PT-2009-1969 · Apache Friends · Xampp
Michael Brooks
·
Publicado
2009-03-20
·
Atualizado
2017-09-29
·
CVE-2008-6499
CVSS v2.0
5.5
Média
| Vetor | AV:N/AC:L/Au:S/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
XAMPP version 1.6.8
Description
The issue allows remote attackers to spoof critical variables by performing an extract operation on the SERVER superglobal array in the security/xamppsecurity.php file. This can be demonstrated by setting the
REMOTE ADDR variable to 127.0.0.1, potentially allowing attackers to manipulate the system.Recommendations
For XAMPP version 1.6.8, consider restricting access to the security/xamppsecurity.php file until a patch is available, or apply a configuration change to prevent the extract operation on the SERVER superglobal array. As a temporary workaround, avoid using the
REMOTE ADDR variable in security-critical operations.Exploit
Correção
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Xampp