CVE-2009-0919 - CVE House
Back to Database
Status published High CVE-2009-0919

XAMPP installs multiple packages with insecure default passwords, which makes...

Vulnerability Description

XAMPP installs multiple packages with insecure default passwords, which makes it easier for remote attackers to obtain access via (1) the "lampp" default password for the "nobody" account within the included ProFTPD installation, (2) a blank default password for the "root" account within the included MySQL installation, (3) a blank default password for the "pma" account within the phpMyAdmin installation, and possibly other unspecified passwords. NOTE: this was originally reported as a problem in DFLabs PTK, but this issue affects any product that is installed within the XAMPP environment, and should not be viewed as a vulnerability within that product. NOTE: DFLabs states that PTK is intended for use in a laboratory with "no contact from / to internet."

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-0919

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

apachefriends

View all reports →

Affected Software

xampp
Vulnerable Versions:
0.1, 0.2, 0.3, 0.4, 0.5, 0.6, 0.6.1, 0.6.2, 0.6.3, 0.6a, 0.7, 0.7.0, 0.7.1, 0.7.2, 0.7.3, 0.7.4, 0.8.1, 0.8.2, 0.9, 1.0, 1.0.1, 1.1, 1.2, 1.3, 1.4, 1.4.2, 1.4.3, 1.4.4, 1.4.5, 1.4.6, 1.4.7, 1.4.8, 1.4.9, 1.4.10, 1.4.11, 1.4.12, 1.4.13, 1.4.14, 1.4.15, 1.4.16, 1.5, 1.5.0, 1.5.1, 1.5.2, 1.5.3, 1.5.4, 1.5.4a, 1.5.5, 1.5.5a, 1.6, 1.6.0, 1.6.0a, 1.6.1, 1.6.2, 1.6.3, 1.6.3a, 1.6.3b, 1.6.4, 1.6.5, 1.6.5a, 1.6.6, 1.6.6a, 1.6.7, 1.6.8, 1.6.8a, 1.7, 1.7.1, development

Timeline

Official Publish: March 16th, 2009
Last Modified: August 7th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.