Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2019-8923

Description

XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. NOTE: This product is discontinued.

POC

Reference

- http://packetstormsecurity.com/files/151756/XAMPP-5.6.8-Cross-Site-Scripting-SQL-Injection.html

- http://seclists.org/fulldisclosure/2019/Feb/43

- https://sourceforge.net/projects/xampp/files/XAMPP%20Windows/5.6.8/

- https://www.exploit-db.com/exploits/46424/

Github

- https://github.com/ARPSyndicate/cvemon