CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
38354 | CVE-2009-0919 | Candidate | XAMPP installs multiple packages with insecure default passwords, which makes it easier for remote attackers to obtain access via (1) the "lampp" default password for the "nobody" account within the included ProFTPD installation, (2) a blank default password for the "root" account within the included MySQL installation, (3) a blank default password for the "pma" account within the phpMyAdmin installation, and possibly other unspecified passwords. NOTE: this was originally reported as a problem in DFLabs PTK, but this issue affects any product that is installed within the XAMPP environment, and should not be viewed as a vulnerability within that product. NOTE: DFLabs states that PTK is intended for use in a laboratory with "no contact from / to internet." | Assigned (20090316) | None (candidate not yet proposed) | View | |
62533 | CVE-2013-2586 | Candidate | XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp and execute cross-site scripting (XSS) attacks via the WriteIntoLocalDisk method. | Assigned (20130315) | None (candidate not yet proposed) | View | |
12284 | CVE-2005-1078 | Candidate | XAMPP 1.4.x has multiple default or null passwords, which allows attackers to gain privileges. | Assigned (20050412) | None (candidate not yet proposed) | View | |
51733 | CVE-2011-3821 | Candidate | xajax 0.6 beta1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by xajax_core/plugin_layer/xajaxScriptPlugin.inc.php and certain other files. | Assigned (20110923) | None (candidate not yet proposed) | View | |
86081 | CVE-2015-8804 | Candidate | x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-384 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors. | Assigned (20160202) | None (candidate not yet proposed) | View |
Page 114 of 20943, showing 5 records out of 104715 total, starting on record 566, ending on 570