Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6vrv-pvc8-f6cm

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows remote attackers to spoof critical variables, as demonstrated by setting the REMOTE_ADDR variable to 127.0.0.1.

security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows remote attackers to spoof critical variables, as demonstrated by setting the REMOTE_ADDR variable to 127.0.0.1.

EPSS

Процентиль: 84%
0.02228
Низкий

Дефекты

CWE-94

Связанные уязвимости

nvd
почти 17 лет назад

security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows remote attackers to spoof critical variables, as demonstrated by setting the REMOTE_ADDR variable to 127.0.0.1.

EPSS

Процентиль: 84%
0.02228
Низкий

Дефекты

CWE-94