6.6 Medium
AI Score
Confidence
Low
0.001 Low
EPSS
Percentile
44.1%
security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows remote attackers to spoof critical variables, as demonstrated by setting the REMOTE_ADDR variable to 127.0.0.1.
exchange.xforce.ibmcloud.com/vulnerabilities/47202
www.exploit-db.com/exploits/7384