Remote Code Execution Vulnerability in XAMPP WebDAV by Apache Friends
CVE-2012-10062
Key Information:
- Vendor
Apache Friends
- Status
- Vendor
- CVE Published:
- 30 August 2025
Badges
What is CVE-2012-10062?
A vulnerability exists in the default WebDAV configuration of XAMPP version 1.7.3 by Apache Friends, allowing remote authenticated attackers to exploit the system. The service accepts HTTP PUT requests using default credentials, enabling attackers to upload malicious PHP scripts. Once these scripts are uploaded, they can be executed through subsequent GET requests, leading to unauthorized code execution on the server. This poses a significant risk to system integrity and data security.
Affected Version(s)
XAMPP * <= 1.7.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved