Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
SHARE

CORE IMPACT v12 - Exploits Update (Wed Nov 16 2011)

Xampp php_self Cross Site Scripting Exploit

Exploits/Cross Site Scripting (XSS)/Known Vulnerabilities  []




Wed Nov 16 2011
XAMPP suffers from multiple XSS issues in several scripts that use the 'PHP_SELF' variable. The vulnerabilities can be triggered in the 'xamppsecurity.php', 'cds.php' and 'perlinfo.pl' because there isn't any filtering to the mentioned variable in the affected scripts. Attackers can exploit these weaknesses to execute arbitrary HTML and script code in a user's browser session.

Exploits Vulnerabiltiy: NOCVE-9999-50264



< Back to Product Updates