vendor:
XAMPP
by:
bi0
3.3
CVSS
MEDIUM
Change Administrative Password
N/A
CWE
Product Name: XAMPP
Affected Version From: 1.7.2002
Affected Version To: 1.7.2002
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP / Windows Vista
2009
XAMPP 1.7.2 Change Administrative Password
At the older versions of xampp 'xamppsecurity.php' was allowed only for localhost but at version 1.7.2 it is accessible by all. And you can change the .htacces user & pass and the phpMyAdmin pass.
Mitigation:
Restrict access to xamppsecurity.php to localhost only.