Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-0919

Опубликовано: 16 мар. 2009
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

XAMPP installs multiple packages with insecure default passwords, which makes it easier for remote attackers to obtain access via (1) the "lampp" default password for the "nobody" account within the included ProFTPD installation, (2) a blank default password for the "root" account within the included MySQL installation, (3) a blank default password for the "pma" account within the phpMyAdmin installation, and possibly other unspecified passwords. NOTE: this was originally reported as a problem in DFLabs PTK, but this issue affects any product that is installed within the XAMPP environment, and should not be viewed as a vulnerability within that product. NOTE: DFLabs states that PTK is intended for use in a laboratory with "no contact from / to internet."

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:apachefriends:xampp:0.1:alpha:solaris:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:0.1:beta:mac_os_x:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:0.2:alpha:solaris:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:0.2:beta:mac_os_x:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:0.3:-:mac_os_x:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:0.3:alpha:solaris:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:0.4:-:mac_os_x:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:0.4:alpha:solaris:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:0.5:-:mac_os_x:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:0.5:beta:solaris:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:0.6:-:mac_os_x:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:0.6:beta:solaris:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:0.6.1:-:mac_os_x:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:0.6.2:-:mac_os_x:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:0.6.3:-:mac_os_x:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:0.6a:-:mac_os_x:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:0.7:beta:solaris:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:0.7.0:-:mac_os_x:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:0.7.1:-:mac_os_x:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:0.7.2:-:mac_os_x:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:0.7.3:-:mac_os_x:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:0.7.4:-:mac_os_x:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:0.8.1:-:solaris:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:0.8.2:-:solaris:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:0.9:-:solaris:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:0.9:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.0:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.0.1:-:mac_os_x:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.1:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.2:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.2:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.3:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.3:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.2:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.2:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.3:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.3:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.4:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.4:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.5:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.5:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.6:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.6:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.7:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.7:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.8:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.8:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.9:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.9:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.10:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.10:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.11:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.11:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.12:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.12:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.13:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.13:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.14:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.14:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.15:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.15:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.16:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.4.16:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.5:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.5.0:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.5.1:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.5.1:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.5.2:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.5.2:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.5.3:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.5.3:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.5.4:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.5.4:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.5.4a:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.5.4a:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.5.5:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.5.5:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.5.5a:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.6:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.6.0:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.6.0a:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.6.1:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.6.1:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.6.2:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.6.2:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.6.3:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.6.3:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.6.3a:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.6.3a:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.6.3b:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.6.4:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.6.4:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.6.5:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.6.5:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.6.5a:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.6.6:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.6.6:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.6.6a:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.6.7:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.6.7:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.6.8:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.6.8a:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.7:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.7:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.7.1:-:linux:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:1.7.1:-:windows:*:*:*:*:*
cpe:2.3:a:apachefriends:xampp:development:-:windows:*:*:*:*:*

EPSS

Процентиль: 82%
0.01687
Низкий

7.5 High

CVSS2

Дефекты

CWE-255

Связанные уязвимости

github
почти 4 года назад

XAMPP installs multiple packages with insecure default passwords, which makes it easier for remote attackers to obtain access via (1) the "lampp" default password for the "nobody" account within the included ProFTPD installation, (2) a blank default password for the "root" account within the included MySQL installation, (3) a blank default password for the "pma" account within the phpMyAdmin installation, and possibly other unspecified passwords. NOTE: this was originally reported as a problem in DFLabs PTK, but this issue affects any product that is installed within the XAMPP environment, and should not be viewed as a vulnerability within that product. NOTE: DFLabs states that PTK is intended for use in a laboratory with "no contact from / to internet."

EPSS

Процентиль: 82%
0.01687
Низкий

7.5 High

CVSS2

Дефекты

CWE-255