PT-2009-3506 · Proftpd+3 · Proftpd+3

Published

2009-03-16

·

Updated

2017-08-17

·

CVE-2009-0919

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions XAMPP (affected versions not specified)
Description The issue concerns insecure default passwords in multiple packages installed by XAMPP. This makes it easier for remote attackers to gain access through various default passwords, including the nobody account in ProFTPD, the root account in MySQL, and the pma account in phpMyAdmin. This issue affects any product installed within the XAMPP environment.
Recommendations For XAMPP, change the default passwords for the nobody account in ProFTPD, the root account in MySQL, and the pma account in phpMyAdmin to secure passwords. As a temporary workaround, consider restricting access to the ProFTPD, MySQL, and phpMyAdmin installations until secure passwords are set. Avoid using default or blank passwords for any accounts within the XAMPP environment to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0919

Affected Products

Mysql Server
Proftpd
Xampp
Phpmyadmin