vendor:
XAMPP
by:
Gionathan "John" Reale, Semen Alexandrovich Lyhin
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: XAMPP
Affected Version From: 3.2.2002
Affected Version To: 3.2.2002
Patch Exists: NO
Related CWE:
CPE: a:xampp_project:xampp:3.2.2
Platforms Tested: Windows 10 64bit with XAMPP 32bit
2018
XAMPP Control Panel 3.2.2 – Buffer Overflow (SEH) (Unicode)
This exploit allows an attacker to execute arbitrary code by exploiting a buffer overflow vulnerability in XAMPP Control Panel version 3.2.2. The exploit involves creating a specially crafted file and pasting its contents into the 'Editor' field in the program.
Mitigation:
Update to the latest version of XAMPP.