XAMPP WebDAV PHP Upload Authentication Bypass RCE
Vulnerability Description
A vulnerability in XAMPP, developed by Apache Friends, version 1.7.3's default WebDAV configuration allows remote authenticated attackers to upload and execute arbitrary PHP code. The WebDAV service, accessible via /webdav/, accepts HTTP PUT requests using default credentials. This permits attackers to upload a malicious PHP payload and trigger its execution via a subsequent GET request, resulting in remote code execution on the server.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-10062
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- theLightCosine
References
More from Apache Friends
View All →Affected Vendor
Apache Friends
View all reports →