Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  wordpress plugins WP Super Cache v0.8.3 Remote File Inclusion  Vulnerability

  Phorum : Permanent Cross-Site Scripting Vulnerabilities

From:MustLive <mustlive_(at)_websecurity.com.ua>
Date:23.07.2009
Subject:Insufficient Authentication, XSS and SQL Injection vulnerabilities in XAMPP

Hello 3APA3A!

I want to warn you about security vulnerabilities in XAMPP.

These are Insufficient Authentication, Cross-Site Scripting and SQL Injection vulnerabilities.

Insufficient Authentication:

http://site/xampp/

There are such sites, where access to admin panel of XAMPP is not restricted by password.

XSS:

POST query at page http://site/xampp/adodb.php

"><script>alert(document.cookie)</script>
In fields: Database server, Host, Username, Password, Current database, Selected table.

SQL Injection:

Attack is conducted during access to admin panel of XAMPP - via above-mentioned Insufficient
Authorization vulnerability or via Insufficient Authorization vulnerability which was found
earlier (http://websecurity.com.ua/3220/).

At page http://site/xampp/adodb.php

cds where 1=0 union select version(),0,0,0
In field Selected table.

Vulnerable are XAMPP 1.6.8 and previous versions. And potentially next versions (including last
version XAMPP 1.7.1).

I mentioned about these vulnerabilities at my site (http://websecurity.com.ua/3233/).

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua

!DSPAM:4a65f256202288653636022!

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server