PT-2006-5737 · Perl Foundation+3 · Perl+3

Thierry Zoller

·

Published

2006-09-26

·

Updated

2025-04-09

·

CVE-2006-4994

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache Friends XAMPP version 1.5.2
Description The issue concerns unquoted Windows search path vulnerabilities in XAMPP. This could allow local users to gain privileges by placing a malicious program file in the %SYSTEMDRIVE%, which would be executed when XAMPP attempts to run certain executables, including FileZillaServer.exe, mysqld-nt.exe, Perl.exe, or xamppcontrol.exe, due to the unquoted "Program Files" pathname.
Recommendations For Apache Friends XAMPP version 1.5.2, consider quoting the "Program Files" pathname to prevent malicious programs from being executed. Additionally, as a temporary workaround, restrict access to the executables FileZillaServer.exe, mysqld-nt.exe, Perl.exe, and xamppcontrol.exe to minimize the risk of exploitation.

Fix

Related Identifiers

CVE-2006-4994

Affected Products

Filezilla Server
Mysql Server
Perl
Xampp