header-logo
Suggest Exploit
vendor:
XAMPP
by:
Talson
6.1
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: XAMPP
Affected Version From: 3.3.2000
Affected Version To: 3.3.2000
Patch Exists: NO
Related CWE: CVE-2023-46517
CPE: a:apache_friends:xampp:3.3.0
Metasploit:
Other Scripts:
Platforms Tested: Windows 11
2023

XAMPP v3.3.0 ‘.ini’ Buffer Overflow (Unicode + SEH)

The exploit involves a buffer overflow vulnerability in XAMPP v3.3.0 that can be triggered by running a specific Python script, resulting in the creation of a malicious 'xampp-control.ini' file. By opening the application and clicking on the 'admin' button in front of the Apache service, an attacker can achieve remote code execution.

Mitigation:

To mitigate this vulnerability, users should ensure they are using the latest version of XAMPP and avoid running untrusted scripts or files.
Source

Exploit-DB raw data: