PT-2006-5737 · Perl Foundation+3 · Perl+3
Thierry Zoller
·
Published
2006-09-26
·
Updated
2025-04-09
·
CVE-2006-4994
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Apache Friends XAMPP version 1.5.2
Description
The issue concerns unquoted Windows search path vulnerabilities in XAMPP. This could allow local users to gain privileges by placing a malicious program file in the %SYSTEMDRIVE%, which would be executed when XAMPP attempts to run certain executables, including
FileZillaServer.exe, mysqld-nt.exe, Perl.exe, or xamppcontrol.exe, due to the unquoted "Program Files" pathname.Recommendations
For Apache Friends XAMPP version 1.5.2, consider quoting the "Program Files" pathname to prevent malicious programs from being executed. Additionally, as a temporary workaround, restrict access to the executables
FileZillaServer.exe, mysqld-nt.exe, Perl.exe, and xamppcontrol.exe to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Filezilla Server
Mysql Server
Perl
Xampp