← Back

CVE-2009-0919

nvd nist
Published: Mar 16, 2009Modified: Apr 23, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

XAMPP installs multiple packages with insecure default passwords, which makes it easier for remote attackers to obtain access via (1) the "lampp" default password for the "nobody" account within the included ProFTPD installation, (2) a blank default password for the "root" account within the included MySQL installation, (3) a blank default password for the "pma" account within the phpMyAdmin installation, and possibly other unspecified passwords. NOTE: this was originally reported as a problem in DFLabs PTK, but this issue affects any product that is installed within the XAMPP environment, and should not be viewed as a vulnerability within that product. NOTE: DFLabs states that PTK is intended for use in a laboratory with "no contact from / to internet."

Affected (109)

Products: Apachefriends: Xampp
1 product
Xampp
Configuration A
109 vulnerable
Vulnerable SoftwareAffected Versions
Apachefriends
Version 0.1 alpha
Version 0.1 beta
Version 0.2 alpha
Version 0.2 beta
Version 0.3
Version 0.3 alpha
Version 0.4
Version 0.4 alpha
Version 0.5
Version 0.5 beta
Version 0.6.1
Version 0.6.2
Version 0.6.3
Version 0.6
Version 0.6 beta
Version 0.6a
Version 0.7.0
Version 0.7.1
Version 0.7.2
Version 0.7.3
Version 0.7.4
Version 0.7 beta
Version 0.8.1
Version 0.8.2
Version 0.9
Version 0.9
Version 1.0.1
Version 1.0
Version 1.1
Version 1.2
Version 1.2
Version 1.3
Version 1.3
Version 1.4.10
Version 1.4.10
Version 1.4.11
Version 1.4.11
Version 1.4.12
Version 1.4.12
Version 1.4.13
Version 1.4.13
Version 1.4.14
Version 1.4.14
Version 1.4.15
Version 1.4.15
Version 1.4.16
Version 1.4.16
Version 1.4.2
Version 1.4.2
Version 1.4.3
Version 1.4.3
Version 1.4.4
Version 1.4.4
Version 1.4.5
Version 1.4.5
Version 1.4.6
Version 1.4.6
Version 1.4.7
Version 1.4.7
Version 1.4.8
Version 1.4.8
Version 1.4.9
Version 1.4.9
Version 1.4
Version 1.4
Version 1.5.0
Version 1.5.1
Version 1.5.1
Version 1.5.2
Version 1.5.2
Version 1.5.3
Version 1.5.3
Version 1.5.4
Version 1.5.4
Version 1.5.4a
Version 1.5.4a
Version 1.5.5
Version 1.5.5
Version 1.5.5a
Version 1.5
Version 1.6.0
Version 1.6.0a
Version 1.6.1
Version 1.6.1
Version 1.6.2
Version 1.6.2
Version 1.6.3
Version 1.6.3
Version 1.6.3a
Version 1.6.3a
Version 1.6.3b
Version 1.6.4
Version 1.6.4
Version 1.6.5
Version 1.6.5
Version 1.6.5a
Version 1.6.6
Version 1.6.6
Version 1.6.6a
Version 1.6.7
Version 1.6.7
Version 1.6.8
Version 1.6.8a
Version 1.6
Version 1.7.1
Version 1.7.1
Version 1.7
Version 1.7
Version development

Related CWEs

References (10)

Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.