XAMPP 'cds-fpdf.php' SQL-injection and HTML Injection Vulnerabilities
BID:107168
CVE-2019-8923 | CVE-2019-8924 |Info
XAMPP 'cds-fpdf.php' SQL-injection and HTML Injection Vulnerabilities
| Bugtraq ID: | 107168 |
| Class: | Input Validation Error |
| CVE: |
CVE-2019-8923 CVE-2019-8924 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 19 2019 12:00AM |
| Updated: | Feb 19 2019 12:00AM |
| Credit: | Unknown |
| Vulnerable: |
XAMPP XAMPP 5.6.8 |
| Not Vulnerable: |
XAMPP XAMPP 5.6.40 |
Discussion
XAMPP 'cds-fpdf.php' SQL-injection and HTML Injection Vulnerabilities
XAMPP is prone to an SQL-injection and multiple HTML Injection vulnerabilities.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
XAMPP 5.6.8 and prior versions are affected.
XAMPP is prone to an SQL-injection and multiple HTML Injection vulnerabilities.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
XAMPP 5.6.8 and prior versions are affected.
Solution / Fix
XAMPP 'cds-fpdf.php' SQL-injection and HTML Injection Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.