PT-2009-1969 · Apache Friends · Xampp
Michael Brooks
·
Published
2009-03-20
·
Updated
2017-09-29
·
CVE-2008-6499
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
XAMPP version 1.6.8
Description
The issue allows remote attackers to spoof critical variables by performing an extract operation on the SERVER superglobal array in the security/xamppsecurity.php file. This can be demonstrated by setting the
REMOTE ADDR variable to 127.0.0.1, potentially allowing attackers to manipulate the system.Recommendations
For XAMPP version 1.6.8, consider restricting access to the security/xamppsecurity.php file until a patch is available, or apply a configuration change to prevent the extract operation on the SERVER superglobal array. As a temporary workaround, avoid using the
REMOTE ADDR variable in security-critical operations.Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xampp