Exploit Release : XAMPP 1.7.3 multiple Vulnerabilities - The Hacker News
Loading
Sign up for Quick Updates

Exploit Release : XAMPP 1.7.3 multiple Vulnerabilities

Author: Mohit Kumar onTuesday, November 02, 2010
Follow Us

Exploit Title: XAMPP <= 1.7.3 multiple vulnerabilites
Author: TheLeader
Software Link: http://www.apachefriends.org/en/xampp-windows.html
Affected Version: 1.7.3 and prior
Tested on Windows XP Hebrew, Service Pack 3
http://images.tblog.com/user_images/1213841656_kinghavoc.gif
I. File disclosure : XAMPP is vulnerable to a remote file disclosure attack.
The vulnerability exists within the web application supplied with XAMPP.
II. Cross Site Scripting : It is interesting to see the same programming error lead to another security vulnerability.Some PHP scripts in the XAMPP dir rely on $_SERVER['PHP_SELF'] for retrieving the "action" tag for HTML forms.This can be exploited to perform Cross Site Scripting attacks.
Exploit Link : http://inj3ct0r.com/exploits/14686
Posted in Categories: , , ,

Author Info

photo of Mohit Kumar

aka 'Unix Root' is Founder and Editor-in-chief of 'The Hacker News'. He is a Security Researcher and Analyst, with experience in various aspects of Information Security. Other than this : He is an Internet Activist, Strong supporter of Anonymous & Wikileaks. Follow him @ Twitter | LinkedIn | | | Facebook Profile